PT-2024-40389 · Openssl · Openssl
Published
2024-01-03
·
Updated
2024-01-03
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 0.6.2
Description
The issue allows an attacker to learn parts of the secret key when they can time decapsulation and forge cipher texts on certain platforms. This does not affect ephemeral usage, such as regular use in TLS.
Recommendations
For versions prior to 0.6.2, update to version 0.6.2 to resolve the issue.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl