PT-2024-40389 · Openssl · Openssl

Published

2024-01-03

·

Updated

2024-01-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.6.2
Description The issue allows an attacker to learn parts of the secret key when they can time decapsulation and forge cipher texts on certain platforms. This does not affect ephemeral usage, such as regular use in TLS.
Recommendations For versions prior to 0.6.2, update to version 0.6.2 to resolve the issue.

Related Identifiers

GHSA-P4V8-JGCV-9G75

Affected Products

Openssl