Mandrake Linux Security Advisory : openssl (MDKSA-2005:096)

High Nessus Plugin ID 18434


The remote Mandrake Linux host is missing one or more security updates.


Colin Percival reported a cache timing attack that could be used to allow a malicious local user to gain portions of cryptographic keys (CVE-2005-0109). The OpenSSL library has been patched to add a new fixed-window mod_exp implementation as default for RSA, DSA, and DH private key operations. The patch was designed to mitigate cache timing and possibly related attacks.


Update the affected packages.

Plugin Details

Severity: High

ID: 18434

File Name: mandrake_MDKSA-2005-096.nasl

Version: $Revision: 1.15 $

Type: local

Published: 2005/06/08

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64openssl0.9.7, p-cpe:/a:mandriva:linux:lib64openssl0.9.7-devel, p-cpe:/a:mandriva:linux:lib64openssl0.9.7-static-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7, p-cpe:/a:mandriva:linux:libopenssl0.9.7-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7-static-devel, p-cpe:/a:mandriva:linux:openssl, cpe:/o:mandrakesoft:mandrake_linux:10.0, cpe:/o:mandrakesoft:mandrake_linux:10.1, x-cpe:/o:mandrakesoft:mandrake_linux:le2005

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2005/06/06

Reference Information

CVE: CVE-2005-0109

MDKSA: 2005:096