Mandrake Linux Security Advisory : openssl (MDKSA-2003:035)

high Nessus Plugin ID 14019

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

Researchers discovered a timing-based attack on RSA keys that OpenSSL is generally vulnerable to, unless RSA blinding is enabled. Patches from the OpenSSL team have been applied to turn RSA blinding on by default.

An extension of the 'Bleichenbacher attack' on RSA with PKS #1 v1.5 padding as used in SSL 3.0 and TSL 1.0 was also created by Czech cryptologists Vlastimil Klima, Ondrej Pokorny, and Tomas Rosa. This attack requires the attacker to open millions of SSL/TLS connections to the server they are attacking. This is done because the server's behaviour when faced with specially crafted RSA ciphertexts can reveal information that would in effect allow the attacker to perform a single RSA private key operation on a ciphertext of their choice, using the server's RSA key. Despite this, the server's RSA key is not compromised at any time. Patches from the OpenSSL team modify SSL/TLS server behaviour to avoid this vulnerability.

Solution

Update the affected packages.

See Also

http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html

http://eprint.iacr.org/2003/052/

https://www.openssl.org/news/secadv/20030317.txt

https://www.openssl.org/news/secadv/20030319.txt

Plugin Details

Severity: High

ID: 14019

File Name: mandrake_MDKSA-2003-035.nasl

Version: 1.21

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:libopenssl0, p-cpe:/a:mandriva:linux:libopenssl0-devel, p-cpe:/a:mandriva:linux:libopenssl0-static-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7, p-cpe:/a:mandriva:linux:libopenssl0.9.7-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7-static-devel, p-cpe:/a:mandriva:linux:openssl, p-cpe:/a:mandriva:linux:openssl-devel, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.0, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0, cpe:/o:mandrakesoft:mandrake_linux:9.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 3/25/2003

Reference Information

CVE: CVE-2003-0131, CVE-2003-0147

MDKSA: 2003:035