PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the servers private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (Karatsuba and normal), a related issue to CVE-2003-0147.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Matrixssl | Peersec_networks | * | 1.0 (including) |