version 1.426, 2003/02/22 22:50:04 |
version 1.427, 2003/02/22 23:16:53 |
|
|
<ul> |
<ul> |
<a name=ssl></a> |
<a name=ssl></a> |
<li><font color=#009000><strong>007: SECURITY FIX: February 22, 2003</strong></font><br> |
<li><font color=#009000><strong>007: SECURITY FIX: February 22, 2003</strong></font><br> |
An information leak can occur via timing by performing a MAC computation |
In |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=8">ssl(8)</a> an information leak can occur via timing by performing a MAC computation |
even if incorrrect block cipher padding has been found. This fix is a |
even if incorrrect block cipher padding has been found. This fix is a |
countermeasure against active attacks where the attacker has to distinguish |
countermeasure against active attacks where the attacker has to distinguish |
between bad padding and a MAC verification error. (CAN-2003-0078). |
between bad padding and a MAC verification error. (CAN-2003-0078). |