This is a different vulnerability. The one you patched two weeks ago was caused by a failure to decrypt messages when the MAC comparison failed. This vulnerability is a timing attack against the RSA algorithms.

The Slashdot discussion is here:

http://slashdot.org/article.pl?sid=03/03/14/0012214&mode=thread&tid=172

The paper is here:

http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html



Christopher Fowler wrote:

Is this a new advisory.  I've patched for a previous timing attack 2
weeks ago.


______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]

Reply via email to