PT-2004-3572 · Peersec · Matrixssl

Publicado

2004-12-31

·

Atualizado

2008-09-05

·

CVE-2004-2682

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PeerSec MatrixSSL versions prior to 1.1
Description The issue allows context-dependent attackers to obtain the server's private key by determining factors using timing differences. This is related to the implementation of RSA and the use of different integer multiplication algorithms, such as "Karatsuba" and normal, during Montgomery reduction.
Recommendations For versions prior to 1.1, consider implementing RSA blinding to prevent timing attacks. As a temporary workaround, restrict access to sensitive operations that rely on the server's private key until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2682

Produtos afetados

Matrixssl