PT-2004-3572 · Peersec · Matrixssl
Published
2004-12-31
·
Updated
2008-09-05
·
CVE-2004-2682
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PeerSec MatrixSSL versions prior to 1.1
Description
The issue allows context-dependent attackers to obtain the server's private key by determining factors using timing differences. This is related to the implementation of RSA and the use of different integer multiplication algorithms, such as "Karatsuba" and normal, during Montgomery reduction.
Recommendations
For versions prior to 1.1, consider implementing RSA blinding to prevent timing attacks. As a temporary workaround, restrict access to sensitive operations that rely on the server's private key until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Matrixssl