OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a fault-based attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 0.9.8i (including) | 0.9.8i (including) |
Openssl | Ubuntu | dapper | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | hardy | * |
Openssl | Ubuntu | intrepid | * |
Openssl | Ubuntu | jaunty | * |
Openssl | Ubuntu | karmic | * |
Openssl | Ubuntu | lucid | * |
Openssl | Ubuntu | upstream | * |