OpenSSL CBC Error Information Leakage Weakness
BID:6884
Info
OpenSSL CBC Error Information Leakage Weakness
| Bugtraq ID: | 6884 |
| Class: | Design Error |
| CVE: |
CVE-2003-0078 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery credited to Brice Canvel, Alain Hiltgen, Serge Vaudenay, and Martin Vuagnoux. |
| Vulnerable: |
Sun SDK (Windows Production Release) 1.4.1 _02 Sun SDK (Windows Production Release) 1.4.1 _01 Sun SDK (Windows Production Release) 1.4.1 Sun SDK (Solaris Production Release) 1.4.1 _02 Sun SDK (Solaris Production Release) 1.4.1 _01 Sun SDK (Solaris Production Release) 1.4.1 Sun SDK (Linux Production Release) 1.4.1 _02 Sun SDK (Linux Production Release) 1.4.1 _01 Sun SDK (Linux Production Release) 1.4.1 Sun ONE Web Server 6.0 SP5 Sun ONE Web Server 6.0 SP4 Sun ONE Web Server 6.0 SP3 Sun ONE Web Server 6.0 SP2 Sun ONE Web Server 6.0 SP1 Sun ONE Web Server 6.0 Sun ONE Application Server 7.0 Standard Edition Sun ONE Application Server 7.0 Platform Edition Sun JSSE 1.0.3 _01 Sun JSSE 1.0.3 Sun JRE (Windows Production Release) 1.4.1 _02 Sun JRE (Windows Production Release) 1.4.1 _01 Sun JRE (Windows Production Release) 1.4.1 Sun JRE (Solaris Production Release) 1.4.1 _02 Sun JRE (Solaris Production Release) 1.4.1 _01 Sun JRE (Solaris Production Release) 1.4.1 Sun Cobalt RaQ XTR Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 Sun Cobalt Qube 3 Oracle Oracle9i Standard Edition 9.2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 8.1.7 Oracle Oracle9i Personal Edition 9.2 Oracle Oracle9i Personal Edition 9.0.1 Oracle Oracle9i Personal Edition 8.1.7 Oracle Oracle9i Enterprise Edition 9.2 .0 Oracle Oracle9i Enterprise Edition 9.0.1 Oracle Oracle9i Enterprise Edition 8.1.7 Oracle Oracle9i Application Server 9.0.3 Oracle Oracle9i Application Server 9.0.2 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle9i Application Server 1.0.2 .1s Oracle Oracle HTTP Server 9.2 .0 Oracle Oracle HTTP Server 9.0.1 Oracle Oracle HTTP Server 8.1.7 OpenSSL Project OpenSSL 0.9.7 beta3 OpenSSL Project OpenSSL 0.9.7 beta2 OpenSSL Project OpenSSL 0.9.7 beta1 OpenSSL Project OpenSSL 0.9.7 OpenSSL Project OpenSSL 0.9.6 h OpenSSL Project OpenSSL 0.9.6 g OpenSSL Project OpenSSL 0.9.6 e OpenSSL Project OpenSSL 0.9.6 d OpenSSL Project OpenSSL 0.9.6 c OpenSSL Project OpenSSL 0.9.6 b OpenSSL Project OpenSSL 0.9.6 a OpenSSL Project OpenSSL 0.9.6 OpenSSL Project OpenSSL 0.9.5 a OpenSSL Project OpenSSL 0.9.5 OpenSSL Project OpenSSL 0.9.4 OpenSSL Project OpenSSL 0.9.3 OpenSSL Project OpenSSL 0.9.2 b OpenSSL Project OpenSSL 0.9.1 c OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 HP Webmin-Based Admin 1.0 .01 HP HP-UX Apache-Based Web Server 1.0 .01 HP Apache-Based Web Server 2.0.43 .00 HP Apache-Based Web Server 1.3.27 .00 FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.8 -PRERELEASE FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 Computer Associates eTrust Security Command Center 1.0 Apple Mac OS X 10.2.4 |
| Not Vulnerable: |
Sun SDK (Windows Production Release) 1.4.1 _03 Sun SDK (Solaris Production Release) 1.4.1 _03 Sun SDK (Linux Production Release) 1.4.1 _03 Sun ONE Web Server 6.0 SP6 Sun ONE Application Server 7.0 UR1 Standard Edition Sun ONE Application Server 7.0 UR1 Platform Edition Sun JSSE 1.0.3 _02 Sun JRE (Windows Production Release) 1.4.1 _03 Sun JRE (Solaris Production Release) 1.4.1 _03 Sun JRE (Linux Production Release) 1.4.1 _03 OpenSSL Project OpenSSL 0.9.7 a OpenSSL Project OpenSSL 0.9.6 i HP Webmin-Based Admin 1.0.1 .01 HP HP-UX Apache-Based Web Server 1.0.1 .01 HP HP-UX Apache-Based Web Server 1.0 .07.01 HP Apache-Based Web Server 1.3.27 .01 |
Discussion
OpenSSL CBC Error Information Leakage Weakness
A side-channel attack against implementations of SSL exists that, through analysis of the timing of certain operations, can reveal sensitive information to an active adversary. This information leaked by vulnerable implementations is reportedly sufficient for an adaptive attack that will ultimately obtain plaintext of a target block of ciphertext.
The information loss was reduced in OpenSSL versions 0.9.6i and 0.9.7a. It is not known if other implementations are vulnerable to this or similar weaknesses.
*It should be noted that this attack is reportedly difficult to exploit and requires that the adversary be a man-in-the-middle.
A side-channel attack against implementations of SSL exists that, through analysis of the timing of certain operations, can reveal sensitive information to an active adversary. This information leaked by vulnerable implementations is reportedly sufficient for an adaptive attack that will ultimately obtain plaintext of a target block of ciphertext.
The information loss was reduced in OpenSSL versions 0.9.6i and 0.9.7a. It is not known if other implementations are vulnerable to this or similar weaknesses.
*It should be noted that this attack is reportedly difficult to exploit and requires that the adversary be a man-in-the-middle.
Solution / Fix
OpenSSL CBC Error Information Leakage Weakness
Solution:
It is reported that certain versions of Computer Associates eTrust Security Command Center are prone to this vulnerability. Customers are advised to contact the vendor for further information pertaining to obtaining and applying appropriate updates.
Hewlett-Packard has released an advisory (HPSBUX0309-280), which contains fix information to address this issue in J2SE and JSSE. Customers are advised to upgrade as soon as possible. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
NetBSD has released an advisory (2003-001) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Administrators and users are advised to upgrade to version 0.9.6i or 0.9.7a. OpenPKG has released upgrade RPMs.
Conectiva has released an advisory (CLA-2003:570) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Debian has released an advisory (DSA 253-1) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux have recommended that users who are running 'dev-libs/openssl' upgrade to 'openssl-0.9.6i' or 'openssl-0.9.7a' as follows:
emerge sync
emerge -u openssl
emerge clean
Mandrake has released an advisory (MDKSA-2003:020) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Trustix has released an advisory (TSLSA-2003-0005) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
EnGarde has released an advisory ([ESA-20030220-005) which addresses this issue. Fix details may be found in the attached advisory.
FreeBSD has released an updated Security Advisory. Users are advised to apply the new patches or to upgrade systems via CVS. Further information is available in the referenced advisory.
OpenBSD has released security patches which address this issue. Further information is available from the OpenBSD eratta pages.
SuSE has released an advisory (SuSE-SA:2003:011) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Apple has released an advisory which contains a fix for this issue. Further information is available from the Apple Security Update page.
Red Hat Linux has released an advisory (RHSA-2003:062-11) containing fixes. Information about obtaining and applying fixes are available in the referenced advisory.
Sun has released updated versions of the affected products to address this issue.
Sun has also released an alert stating that this issue has been addressed in the latest release of JSSE, SDK, and JRE.
HP has released advisory HPSBUX0303-248 (rev. 1) to address this issue.
HP has released advisory HPSBUX0303-248 (rev. 2) to address this issue.
Oracle has released an advisory and patches to address this issue. User are advised to obtain patches from the Oracle metalink site listed in references.
Fixes available:
OpenBSD OpenBSD 3.2
Sun Cobalt RaQ 4
Sun Cobalt RaQ 550
Sun Cobalt RaQ XTR
Sun Cobalt Qube 3
OpenBSD OpenBSD 3.1
OpenSSL Project OpenSSL 0.9.3
OpenSSL Project OpenSSL 0.9.4
OpenSSL Project OpenSSL 0.9.5 a
OpenSSL Project OpenSSL 0.9.5
OpenSSL Project OpenSSL 0.9.6 d
OpenSSL Project OpenSSL 0.9.6 c
OpenSSL Project OpenSSL 0.9.6 e
OpenSSL Project OpenSSL 0.9.6 h
OpenSSL Project OpenSSL 0.9.6 a
OpenSSL Project OpenSSL 0.9.6
OpenSSL Project OpenSSL 0.9.6 b
OpenSSL Project OpenSSL 0.9.6 g
OpenSSL Project OpenSSL 0.9.7 beta2
OpenSSL Project OpenSSL 0.9.7 beta1
OpenSSL Project OpenSSL 0.9.7 beta3
OpenSSL Project OpenSSL 0.9.7
HP HP-UX Apache-Based Web Server 1.0 .01
Sun JSSE 1.0.3 _01
Sun JSSE 1.0.3
HP Apache-Based Web Server 1.3.27 .00
Sun SDK (Solaris Production Release) 1.4.1
Sun JRE (Solaris Production Release) 1.4.1 _02
Sun JRE (Solaris Production Release) 1.4.1
Sun SDK (Solaris Production Release) 1.4.1 _01
Sun SDK (Windows Production Release) 1.4.1
Sun JRE (Solaris Production Release) 1.4.1 _01
Sun SDK (Windows Production Release) 1.4.1 _02
Sun JRE (Windows Production Release) 1.4.1
Sun JRE (Windows Production Release) 1.4.1 _02
Sun SDK (Linux Production Release) 1.4.1
Sun SDK (Solaris Production Release) 1.4.1 _02
Sun SDK (Windows Production Release) 1.4.1 _01
Sun SDK (Linux Production Release) 1.4.1 _02
Sun JRE (Windows Production Release) 1.4.1 _01
Sun SDK (Linux Production Release) 1.4.1 _01
Apple Mac OS X 10.2.4
HP Apache-Based Web Server 2.0.43 .00
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.6.2
FreeBSD FreeBSD 4.7
FreeBSD FreeBSD 4.7 -STABLE
FreeBSD FreeBSD 4.8 -PRERELEASE
FreeBSD FreeBSD 5.0
Sun ONE Web Server 6.0 SP5
Sun ONE Web Server 6.0 SP4
Sun ONE Web Server 6.0
Sun ONE Web Server 6.0 SP2
Sun ONE Web Server 6.0 SP3
Sun ONE Web Server 6.0 SP1
Sun ONE Application Server 7.0 Standard Edition
Sun ONE Application Server 7.0 Platform Edition
Solution:
It is reported that certain versions of Computer Associates eTrust Security Command Center are prone to this vulnerability. Customers are advised to contact the vendor for further information pertaining to obtaining and applying appropriate updates.
Hewlett-Packard has released an advisory (HPSBUX0309-280), which contains fix information to address this issue in J2SE and JSSE. Customers are advised to upgrade as soon as possible. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
NetBSD has released an advisory (2003-001) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Administrators and users are advised to upgrade to version 0.9.6i or 0.9.7a. OpenPKG has released upgrade RPMs.
Conectiva has released an advisory (CLA-2003:570) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Debian has released an advisory (DSA 253-1) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux have recommended that users who are running 'dev-libs/openssl' upgrade to 'openssl-0.9.6i' or 'openssl-0.9.7a' as follows:
emerge sync
emerge -u openssl
emerge clean
Mandrake has released an advisory (MDKSA-2003:020) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Trustix has released an advisory (TSLSA-2003-0005) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
EnGarde has released an advisory ([ESA-20030220-005) which addresses this issue. Fix details may be found in the attached advisory.
FreeBSD has released an updated Security Advisory. Users are advised to apply the new patches or to upgrade systems via CVS. Further information is available in the referenced advisory.
OpenBSD has released security patches which address this issue. Further information is available from the OpenBSD eratta pages.
SuSE has released an advisory (SuSE-SA:2003:011) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Apple has released an advisory which contains a fix for this issue. Further information is available from the Apple Security Update page.
Red Hat Linux has released an advisory (RHSA-2003:062-11) containing fixes. Information about obtaining and applying fixes are available in the referenced advisory.
Sun has released updated versions of the affected products to address this issue.
Sun has also released an alert stating that this issue has been addressed in the latest release of JSSE, SDK, and JRE.
HP has released advisory HPSBUX0303-248 (rev. 1) to address this issue.
HP has released advisory HPSBUX0303-248 (rev. 2) to address this issue.
Oracle has released an advisory and patches to address this issue. User are advised to obtain patches from the Oracle metalink site listed in references.
Fixes available:
OpenBSD OpenBSD 3.2
-
OpenBSD 007_ssl.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/007_ssl.patch
Sun Cobalt RaQ 4
-
Sun RaQ4-All-Security-2.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-All-Security-2.0. 1-16343.pkg
Sun Cobalt RaQ 550
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg
Sun Cobalt RaQ XTR
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg -
Sun RaQXTR-All-Security-1.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16343.pkg
Sun Cobalt Qube 3
-
Sun Qube3-All-Security-4.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0 .1-16343.pkg
OpenBSD OpenBSD 3.1
-
OpenBSD 021_ssl.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/021_ssl.patch
OpenSSL Project OpenSSL 0.9.3
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.4
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.5 a
-
Mandrake openssl-0.9.5a-9.4mdk.i586.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake openssl-devel-0.9.5a-9.4mdk.i586.rpm
Mandrake Linux 7.2
http://www.mandrakesecure.net/en/ftp.php -
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.5
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.6 d
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.6 c
-
Conectiva openssl-0.9.6-4U60_5cl.i386.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/openssl-0.9.6-4U60_5cl.i3 86.rpm -
Conectiva openssl-0.9.6-4U60_5cl.src.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/openssl-0.9.6-4U60_5cl.s rc.rpm -
Conectiva openssl-0.9.6c-2U80_4cl.i386.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-0.9.6c-2U80_4cl.i38 6.rpm -
Conectiva openssl-0.9.6c-2U80_4cl.src.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/SRPMS/openssl-0.9.6c-2U80_4cl.sr c.rpm -
Conectiva openssl-devel-0.9.6-4U60_5cl.i386.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/openssl-devel-0.9.6-4U60_ 5cl.i386.rpm -
Conectiva openssl-devel-0.9.6c-2U80_4cl.i386.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-0.9.6c-2U80_4 cl.i386.rpm -
Conectiva openssl-devel-static-0.9.6c-2U80_4cl.i386.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-static-0.9.6c -2U80_4cl.i386.rpm -
Conectiva openssl-doc-0.9.6c-2U80_4cl.i386.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-doc-0.9.6c-2U80_4cl .i386.rpm -
Conectiva openssl-progs-0.9.6c-2U80_4cl.i386.rpm
Conectiva Linux Version 8.0
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-progs-0.9.6c-2U80_4 cl.i386.rpm -
Debian libssl-dev_0.9.6c-2.woody.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_alpha.deb -
Debian libssl-dev_0.9.6c-2.woody.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_arm.deb -
Debian libssl-dev_0.9.6c-2.woody.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_hppa.deb -
Debian libssl-dev_0.9.6c-2.woody.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_i386.deb -
Debian libssl-dev_0.9.6c-2.woody.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_ia64.deb -
Debian libssl-dev_0.9.6c-2.woody.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_m68k.deb -
Debian libssl-dev_0.9.6c-2.woody.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_mips.deb -
Debian libssl-dev_0.9.6c-2.woody.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_mipsel.deb -
Debian libssl-dev_0.9.6c-2.woody.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_powerpc.deb -
Debian libssl-dev_0.9.6c-2.woody.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_s390.deb -
Debian libssl-dev_0.9.6c-2.woody.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9. 6c-2.woody.2_sparc.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_alpha.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_arm.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_hppa.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_i386.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_ia64.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_m68k.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_mips.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_mipsel.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_powerpc.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_s390.deb -
Debian libssl0.9.6_0.9.6c-2.woody.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9 .6c-2.woody.2_sparc.deb -
Debian openssl_0.9.6c-2.woody.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_alpha.deb -
Debian openssl_0.9.6c-2.woody.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_arm.deb -
Debian openssl_0.9.6c-2.woody.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_hppa.deb -
Debian openssl_0.9.6c-2.woody.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_i386.deb -
Debian openssl_0.9.6c-2.woody.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_ia64.deb -
Debian openssl_0.9.6c-2.woody.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_m68k.deb -
Debian openssl_0.9.6c-2.woody.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_mips.deb -
Debian openssl_0.9.6c-2.woody.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_mipsel.deb -
Debian openssl_0.9.6c-2.woody.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_powerpc.deb -
Debian openssl_0.9.6c-2.woody.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_s390.deb -
Debian openssl_0.9.6c-2.woody.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c- 2.woody.2_sparc.deb -
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz -
SuSE openssl-0.9.6c-83.i386.patch.rpm
//ftp.suse.com/pub/suse/i386/update/8.0/sec1/openssl-0.9.6c-83.i386.pa tch.rpm -
SuSE openssl-0.9.6c-83.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/sec1/openssl-0.9.6c-83.i38 6.rpm
OpenSSL Project OpenSSL 0.9.6 e
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.6 h
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz
OpenSSL Project OpenSSL 0.9.6 a
-
Conectiva openssl-0.9.6a-3U70_5cl.i386.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-0.9.6a-3U70_5cl.i 386.rpm -
Conectiva openssl-0.9.6a-3U70_5cl.src.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/openssl-0.9.6a-3U70_5cl. src.rpm -
Conectiva openssl-devel-0.9.6a-3U70_5cl.i386.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-devel-0.9.6a-3U70 _5cl.i386.rpm -
Conectiva openssl-devel-static-0.9.6a-3U70_5cl.i386.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-devel-static-0.9. 6a-3U70_5cl.i386.rpm -
Conectiva openssl-doc-0.9.6a-3U70_5cl.i386.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-doc-0.9.6a-3U70_5 cl.i386.rpm -
Conectiva openssl-progs-0.9.6a-3U70_5cl.i386.rpm
Conectiva Linux Version 7.0
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-progs-0.9.6a-3U70 _5cl.i386.rpm -
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz -
SuSE openssl-0.9.6a-28.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/sec1/openssl-0.9.6a-28.ppc. rpm -
SuSE openssl-0.9.6a-78.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/sec1/openssl-0.9.6a-78.i38 6.rpm -
SuSE openssl-0.9.6a-78.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/sec1/openssl-0.9.6a-78.i38 6.rpm
OpenSSL Project OpenSSL 0.9.6
-
Conectiva openssl-0.9.6-4U60_5cl.i386.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/openssl-0.9.6-4U60_5cl.i3 86.rpm -
Conectiva openssl-0.9.6-4U60_5cl.src.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/openssl-0.9.6-4U60_5cl.s rc.rpm -
Conectiva openssl-devel-0.9.6-4U60_5cl.i386.rpm
Conectiva Linux Version 6.0
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/openssl-devel-0.9.6-4U60_ 5cl.i386.rpm -
EnGarde Secure Linux openssl-0.9.6-1.0.18.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/openssl-0.9 .6-1.0.18.i386.rpm -
EnGarde Secure Linux openssl-0.9.6-1.0.18.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/openssl-0.9 .6-1.0.18.i686.rpm -
EnGarde Secure Linux openssl-misc-0.9.6-1.0.18.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/openssl-mis c-0.9.6-1.0.18.i386.rpm -
EnGarde Secure Linux openssl-misc-0.9.6-1.0.18.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/openssl-mis c-0.9.6-1.0.18.i686.rpm -
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz -
Trustix openssl-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssl-0.9.6-12tr. i586.rpm -
Trustix openssl-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssl-0.9.6-12tr. i586.rpm -
Trustix openssl-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssl-0.9.6-12tr. i586.rpm -
Trustix openssl-devel-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssl-devel-0.9.6 -12tr.i586.rpm -
Trustix openssl-devel-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssl-devel-0.9.6 -12tr.i586.rpm -
Trustix openssl-devel-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssl-devel-0.9.6 -12tr.i586.rpm -
Trustix openssl-python-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssl-python-0.9. 6-12tr.i586.rpm -
Trustix openssl-python-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssl-python-0.9. 6-12tr.i586.rpm -
Trustix openssl-python-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssl-python-0.9. 6-12tr.i586.rpm -
Trustix openssl-support-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/openssl-support-0.9 .6-12tr.i586.rpm -
Trustix openssl-support-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/openssl-support-0.9 .6-12tr.i586.rpm -
Trustix openssl-support-0.9.6-12tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/openssl-support-0.9 .6-12tr.i586.rpm
OpenSSL Project OpenSSL 0.9.6 b
-
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz -
SuSE openssl-0.9.6b-147.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/sec1/openssl-0.9.6b-147.ppc .rpm -
SuSE openssl-0.9.6b-154.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/sec1/openssl-0.9.6b-154.i3 86.rpm -
SuSE openssl-0.9.6b-87.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/sec1/openssl-0.9.6b-87.sp arc.rpm
OpenSSL Project OpenSSL 0.9.6 g
-
Conectiva openssl-0.9.6g-64.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/i386/RPMS.core/openssl-0.9.6g-64 .i586.rpm -
Conectiva openssl-devel-0.9.6g-64.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/i386/RPMS.core/openssl-devel-0.9 .6g-64.i586.rpm -
HP HP-UX Apache-Based Web Server v.1.0.01.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE -
HP hp-ux apache-based web server v.1.0.07.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE -
OpenPKG openssl-0.9.6g-1.1.1.src.rpm
ftp://ftp.openpkg.org/release/1.1/UPD/openssl-0.9.6g-1.1.1.src.rpm -
OpenSSL Project openssl-0.9.6i.tar.gz
OpenSSL 0.9.6i upgrade.
http://www.openssl.org/source/openssl-0.9.6i.tar.gz -
SuSE openssl-0.9.6g-55.i586.patch.rpm
//ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/openssl-0.9.6g-55.i58 6.patch.rpm -
SuSE openssl-0.9.6g-55.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/openssl-0.9.6g-55 .i586.rpm
OpenSSL Project OpenSSL 0.9.7 beta2
-
OpenSSL Project openssl-0.9.7a.tar.gz
OpenSSL 0.9.7a upgrade.
http://www.openssl.org/source/openssl-0.9.7a.tar.gz
OpenSSL Project OpenSSL 0.9.7 beta1
-
OpenSSL Project openssl-0.9.7a.tar.gz
OpenSSL 0.9.7a upgrade.
http://www.openssl.org/source/openssl-0.9.7a.tar.gz
OpenSSL Project OpenSSL 0.9.7 beta3
-
OpenSSL Project openssl-0.9.7a.tar.gz
OpenSSL 0.9.7a upgrade.
http://www.openssl.org/source/openssl-0.9.7a.tar.gz
OpenSSL Project OpenSSL 0.9.7
-
OpenPKG openssl-0.9.7-1.2.1.src.rpm
ftp://ftp.openpkg.org/release/1.2/UPD/openssl-0.9.7-1.2.1.src.rpm
HP HP-UX Apache-Based Web Server 1.0 .01
-
HP HP-UX Apache-Based Web Server v.1.0.01.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE -
HP hp-ux apache-based web server v.1.0.07.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE
Sun JSSE 1.0.3 _01
-
Sun JSSE 1.0.3_02
http://java.sun.com/products/jsse/index-103.html
Sun JSSE 1.0.3
-
Sun JSSE 1.0.3_02
http://java.sun.com/products/jsse/index-103.html
HP Apache-Based Web Server 1.3.27 .00
-
HP Apache-Based Web Server 1.3.27.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=B9415AA132701 -
HP hp-ux apache-based web server v.1.0.07.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE
Sun SDK (Solaris Production Release) 1.4.1
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Solaris Production Release) 1.4.1 _02
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Solaris Production Release) 1.4.1
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Solaris Production Release) 1.4.1 _01
-
Sun SDK and JRE 1.4.0_03 (Solaris Production Release)
http://java.sun.com/j2se/1.4/ -
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Windows Production Release) 1.4.1
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Solaris Production Release) 1.4.1 _01
-
Sun SDK and JRE 1.4.0_03 (Solaris Production Release)
http://java.sun.com/j2se/1.4/ -
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Windows Production Release) 1.4.1 _02
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Windows Production Release) 1.4.1
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Windows Production Release) 1.4.1 _02
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Linux Production Release) 1.4.1
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Solaris Production Release) 1.4.1 _02
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Windows Production Release) 1.4.1 _01
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Linux Production Release) 1.4.1 _02
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun JRE (Windows Production Release) 1.4.1 _01
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Sun SDK (Linux Production Release) 1.4.1 _01
-
Sun SDK and JRE 1.4.0_03 (Windows Production Release)
http://java.sun.com/j2se
Apple Mac OS X 10.2.4
-
Apple 1024SecUpd2003-03-03.dmg
http://www.info.apple.com/kbnum/n120195
HP Apache-Based Web Server 2.0.43 .00
-
HP hp-ux apache-based web server v.1.0.07.01
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=HPUXWSSUITE
FreeBSD FreeBSD 4.6
-
FreeBSD openssl50.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl50.patc h.gz
FreeBSD FreeBSD 4.6.2
-
FreeBSD openssl462.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl462.pat ch.gz
FreeBSD FreeBSD 4.7
-
FreeBSD openssl47.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl47.patc h.gz -
FreeBSD openssl50.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl50.patc h.gz
FreeBSD FreeBSD 4.7 -STABLE
-
FreeBSD openssl4s.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl4s.patc h.gz
FreeBSD FreeBSD 4.8 -PRERELEASE
-
FreeBSD openssl4s.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl4s.patc h.gz
FreeBSD FreeBSD 5.0
-
FreeBSD openssl50.patch.gz
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:02/openssl50.patc h.gz
Sun ONE Web Server 6.0 SP5
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Web Server 6.0 SP4
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Web Server 6.0
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Web Server 6.0 SP2
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Web Server 6.0 SP3
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Web Server 6.0 SP1
-
Sun One Web Server 6.0 Service Pack 6
http://wwws.sun.com/software/download/products/3f186391.html
Sun ONE Application Server 7.0 Standard Edition
-
Sun ONE Application Server 7.0 Update Release 1 Standard Edition
http://wwws.sun.com/software/download/products/3ec3e772.html
Sun ONE Application Server 7.0 Platform Edition
-
Sun ONE Application Server 7.0 Update Release 1 Platform Edition
http://wwws.sun.com/software/download/products/3ec1008e.html
References
OpenSSL CBC Error Information Leakage Weakness
References:
References:
- Apple Security Updates (Apple)
- OpenBSD 3.2 release errata & patch list (OpenBSD)
- Oracle Support Metalink (Oracle)
- SSL Update for CERT CA200326 and older SSL issues (Oracle)
- Sun Alert ID: 54147 (Sun)
- Sun Alert ID: 56380 (Sun)
- Sun Alert ID:54147 Timing Attack With Cipher Block Chaining (CBC) Mode Ciphers (Sun Microsystems)
- Timing-based attacks on SSL/TLS with CBC encryption (OpenSSL Project)
- TLS timing attack on OpenSSL [can-2003-78] [bid 6884] exploit ("Martin Vuagnoux"
)