Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
BID:13785
Info
Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
| Bugtraq ID: | 13785 |
| Class: | Design Error |
| CVE: |
CVE-2005-1797 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery of this issue is credited to Daniel J. Bernstein. |
| Vulnerable: |
OpenSSL Project OpenSSL 0.9.7 d OpenSSL Project OpenSSL 0.9.7 c OpenSSL Project OpenSSL 0.9.7 beta3 OpenSSL Project OpenSSL 0.9.7 beta2 OpenSSL Project OpenSSL 0.9.7 beta1 OpenSSL Project OpenSSL 0.9.7 b OpenSSL Project OpenSSL 0.9.7 a OpenSSL Project OpenSSL 0.9.7 OpenSSL Project OpenSSL 0.9.6 m OpenSSL Project OpenSSL 0.9.6 l OpenSSL Project OpenSSL 0.9.6 k OpenSSL Project OpenSSL 0.9.6 j OpenSSL Project OpenSSL 0.9.6 i OpenSSL Project OpenSSL 0.9.6 h OpenSSL Project OpenSSL 0.9.6 g OpenSSL Project OpenSSL 0.9.6 f OpenSSL Project OpenSSL 0.9.6 e OpenSSL Project OpenSSL 0.9.6 d OpenSSL Project OpenSSL 0.9.6 c OpenSSL Project OpenSSL 0.9.6 b OpenSSL Project OpenSSL 0.9.6 a OpenSSL Project OpenSSL 0.9.6 OpenSSL Project OpenSSL 0.9.5 a OpenSSL Project OpenSSL 0.9.5 OpenSSL Project OpenSSL 0.9.4 OpenSSL Project OpenSSL 0.9.3 OpenSSL Project OpenSSL 0.9.2 b OpenSSL Project OpenSSL 0.9.1 c AES AES (Rijndael) |
| Not Vulnerable: | |
Discussion
Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
High-speed implementations of AES are prone to a timing attack vulnerability. The attack is based on observations of time taken to complete certain critical AES cryptographic functions (Input dependant Table lookups).
An attacker may theoretically exploit this issue to retrieve an entire AES secret key from a target vulnerable AES implementation.
High-speed implementations of AES are prone to a timing attack vulnerability. The attack is based on observations of time taken to complete certain critical AES cryptographic functions (Input dependant Table lookups).
An attacker may theoretically exploit this issue to retrieve an entire AES secret key from a target vulnerable AES implementation.
Exploit / POC
Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Advanced Encryption Standard Cache Timing Key Disclosure Vulnerability
References:
References:
- Cache-Timing Attacks on AES (Daniel J. Bernstein)
- The Advanced Encryption Standard (Rijndael) (jsavard)