Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: mod_ssl (200303-23)
Date: Tue, 25 Mar 2003 17:45:30
Message-Id: 20030325101317.4E0F15763@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200303-23
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : mod_ssl
9 SUMMARY : timing based attack
10 DATE : 2003-03-25 10:14 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <2.8.14
13 FIXED VERSION : >=2.8.14
14 CVE : CAN-2003-0147
15
16 - - ---------------------------------------------------------------------
17
18 - From advisory:
19
20 "Researchers have discovered a timing attack on RSA keys, to which
21 OpenSSL is generally vulnerable, unless RSA blinding has been turned
22 on."
23
24 Read the full advisory at
25 http://www.openssl.org/news/secadv_20030317.txt
26
27 SOLUTION
28
29 It is recommended that all Gentoo Linux users who are running
30 net-www/mod_ssl upgrade to mod_ssl-2.8.14 as follows:
31
32 emerge sync
33 emerge mod_ssl
34 emerge clean
35
36 - - ---------------------------------------------------------------------
37 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
38 - - ---------------------------------------------------------------------
39 -----BEGIN PGP SIGNATURE-----
40 Version: GnuPG v1.2.1 (GNU/Linux)
41
42 iD8DBQE+gCv1fT7nyhUpoZMRAum/AJ9q76uO5cwCTdbwY2BA1xEAQaY8dgCdEPQF
43 iE3hH2SYHAEHM7QUhRuGSeo=
44 =b1yN
45 -----END PGP SIGNATURE-----