OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the servers private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (Karatsuba and normal).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openpkg | Openpkg | * | * |
Openpkg | Openpkg | 1.1 (including) | 1.1 (including) |
Openpkg | Openpkg | 1.2 (including) | 1.2 (including) |
Openssl | Openssl | 0.9.6 (including) | 0.9.6 (including) |
Openssl | Openssl | 0.9.6a (including) | 0.9.6a (including) |
Openssl | Openssl | 0.9.6b (including) | 0.9.6b (including) |
Openssl | Openssl | 0.9.6c (including) | 0.9.6c (including) |
Openssl | Openssl | 0.9.6d (including) | 0.9.6d (including) |
Openssl | Openssl | 0.9.6e (including) | 0.9.6e (including) |
Openssl | Openssl | 0.9.6g (including) | 0.9.6g (including) |
Openssl | Openssl | 0.9.6h (including) | 0.9.6h (including) |
Openssl | Openssl | 0.9.6i (including) | 0.9.6i (including) |
Openssl | Openssl | 0.9.7 (including) | 0.9.7 (including) |
Openssl | Openssl | 0.9.7a (including) | 0.9.7a (including) |
Stunnel | Stunnel | 3.7 (including) | 3.7 (including) |
Stunnel | Stunnel | 3.8 (including) | 3.8 (including) |
Stunnel | Stunnel | 3.9 (including) | 3.9 (including) |
Stunnel | Stunnel | 3.10 (including) | 3.10 (including) |
Stunnel | Stunnel | 3.11 (including) | 3.11 (including) |
Stunnel | Stunnel | 3.12 (including) | 3.12 (including) |
Stunnel | Stunnel | 3.13 (including) | 3.13 (including) |
Stunnel | Stunnel | 3.14 (including) | 3.14 (including) |
Stunnel | Stunnel | 3.15 (including) | 3.15 (including) |
Stunnel | Stunnel | 3.16 (including) | 3.16 (including) |
Stunnel | Stunnel | 3.17 (including) | 3.17 (including) |
Stunnel | Stunnel | 3.18 (including) | 3.18 (including) |
Stunnel | Stunnel | 3.19 (including) | 3.19 (including) |
Stunnel | Stunnel | 3.20 (including) | 3.20 (including) |
Stunnel | Stunnel | 3.21 (including) | 3.21 (including) |
Stunnel | Stunnel | 3.22 (including) | 3.22 (including) |
Stunnel | Stunnel | 4.0 (including) | 4.0 (including) |
Stunnel | Stunnel | 4.01 (including) | 4.01 (including) |
Stunnel | Stunnel | 4.02 (including) | 4.02 (including) |
Stunnel | Stunnel | 4.03 (including) | 4.03 (including) |
Stunnel | Stunnel | 4.04 (including) | 4.04 (including) |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux 6.2 | RedHat | * | |
Red Hat Linux 7.0 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.1 | RedHat | * | |
Red Hat Linux 7.2 | RedHat | * | |
Red Hat Linux 7.3 | RedHat | * | |
Red Hat Linux 8.0 | RedHat | * | |
Red Hat Linux 9 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Red Hat Stronghold 3 | RedHat | * | |
Red Hat Stronghold 4 | RedHat | * | |
Openssl | Ubuntu | dapper | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | edgy | * |
Openssl | Ubuntu | feisty | * |
Openssl097 | Ubuntu | dapper | * |
Openssl097 | Ubuntu | devel | * |
Openssl097 | Ubuntu | edgy | * |
Openssl097 | Ubuntu | feisty | * |