patches available for RSA timing attacks
"Todd C. Miller" <[email protected]>
| Newsgroups | gmane.os.openbsd.security.announce |
|---|---|
| Message-ID | <[email protected]> |
Researchers have discovered a timing attack on RSA keys to which
OpenSSL is vulnerable. OpenBSD patches are now available.
The following paper describes the attack in detail:
http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf
The patches have already been committed to OpenBSD-current and the
3.1 and 3.2 -stable branches. For those who wish to manually
patch their systems, the following patches are available.
Patch for OpenBSD 3.1:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/024_blinding.patch
Patch for OpenBSD 3.2:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/011_blinding.patch
The OpenSSL advisory (from which the patches are derived) is:
http://www.openssl.org/news/secadv_20030317.txt