patches available for RSA timing attacks

"Todd C. Miller" <[email protected]>
Newsgroups gmane.os.openbsd.security.announce
Message-ID <[email protected]>
Researchers have discovered a timing attack on RSA keys to which
OpenSSL is vulnerable.  OpenBSD patches are now available.
The following paper describes the attack in detail:
    http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf

The patches have already been committed to OpenBSD-current and the
3.1 and 3.2 -stable branches.  For those who wish to manually
patch their systems, the following patches are available.

Patch for OpenBSD 3.1:
    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/024_blinding.patch

Patch for OpenBSD 3.2:
    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/011_blinding.patch

The OpenSSL advisory (from which the patches are derived) is:
    http://www.openssl.org/news/secadv_20030317.txt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.