Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50701
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2003:035 (openssl)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to openssl
announced via advisory MDKSA-2003:035.

Researchers discovered a timing-based attack on RSA keys that OpenSSL
is generally vulnerable to, unless RSA blinding is enabled. Patches
from the OpenSSL team have been applied to turn RSA blinding on by
default.

An extension of the Bleichenbacher attack on RSA with PKS #1 v1.5
padding as used in SSL 3.0 and TSL 1.0 was also created by Czech
cryptologists Vlastimil Klima, Ondrej Pokorny, and Tomas Rosa. This
attack requires the attacker to open millions of SSL/TLS connections to
the server they are attacking. This is done because the server's
behaviour when faced with specially crafted RSA ciphertexts can reveal
information that would in effect allow the attacker to perform a single
RSA private key operation on a ciphertext of their choice, using the
server's RSA key. Despite this, the server's RSA key is not
compromised at any time. Patches from the OpenSSL team modify SSL/TLS
server behaviour to avoid this vulnerability.

Affected versions: 7.2, 8.0, 8.1, 8.2, 9.0, 9.1,
Corporate Server 2.1,

Multi Network Firewall 8.2,

Single Network Firewall 7.2


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:035
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0131
http://www.openssl.org/news/secadv_20030317.txt
http://www.openssl.org/news/secadv_20030319.txt
http://eprint.iacr.org/2003/052/
http://crypto.stanford.edu/~
dabo/abstracts/ssl-timing.html

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0147
http://www.securityfocus.com/archive/1/316165/30/25370/threaded
Bugtraq: 20030313 Vulnerability in OpenSSL (Google Search)
http://marc.info/?l=bugtraq&m=104766550528628&w=2
Bugtraq: 20030317 [ADVISORY] Timing Attack on OpenSSL (Google Search)
http://marc.info/?l=bugtraq&m=104792570615648&w=2
Bugtraq: 20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl) (Google Search)
http://marc.info/?l=bugtraq&m=104819602408063&w=2
Bugtraq: 20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL (Google Search)
Bugtraq: 20030327 Immunix Secured OS 7+ openssl update (Google Search)
http://www.securityfocus.com/archive/1/316577/30/25310/threaded
Caldera Security Advisory: CSSA-2003-014.0
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt
CERT/CC vulnerability note: VU#997481
http://www.kb.cert.org/vuls/id/997481
Conectiva Linux advisory: CLA-2003:625
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625
Debian Security Information: DSA-288 (Google Search)
http://www.debian.org/security/2003/dsa-288
En Garde Linux Advisory: ESA-20030320-010
FreeBSD Security Advisory: FreeBSD-SA-03:06
http://marc.info/?l=bugtraq&m=104829040921835&w=2
http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml
http://marc.info/?l=bugtraq&m=104861762028637&w=2
Immunix Linux Advisory: IMNX-2003-7+-001-01
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035
http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A466
http://www.redhat.com/support/errata/RHSA-2003-101.html
http://www.redhat.com/support/errata/RHSA-2003-102.html
RedHat Security Advisories: RHSA-2003:205
SGI Security Advisory: 20030501-01-I
ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html
Common Vulnerability Exposure (CVE) ID: CVE-2003-0131
BugTraq ID: 7148
http://www.securityfocus.com/bid/7148
Bugtraq: 20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding (Google Search)
http://marc.info/?l=bugtraq&m=104811162730834&w=2
Bugtraq: 20030324 GLSA: openssl (200303-20) (Google Search)
http://marc.info/?l=bugtraq&m=104852637112330&w=2
CERT/CC vulnerability note: VU#888801
http://www.kb.cert.org/vuls/id/888801
http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2003:035
http://eprint.iacr.org/2003/052/
http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html
NETBSD Security Advisory: NetBSD-SA2003-007
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc
http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A461
SuSE Security Announcement: SuSE-SA:2003:024 (Google Search)
https://lists.opensuse.org/opensuse-security-announce/2003-04/msg00005.html
http://marc.info/?l=bugtraq&m=104878215721135&w=2
XForce ISS Database: ssl-premaster-information-leak(11586)
https://exchange.xforce.ibmcloud.com/vulnerabilities/11586
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.