Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.703296
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 3296-1 (libcrypto++ - security update)
Resumen:Evgeny Sidorov discovered that;libcrypto++, a general purpose C++ cryptographic library, did not properly;implement blinding to mask private key operations for the Rabin-Williams;digital signature algorithm. This could allow remote attackers to mount a;timing attack and retrieve the user's private key.
Descripción:Summary:
Evgeny Sidorov discovered that
libcrypto++, a general purpose C++ cryptographic library, did not properly
implement blinding to mask private key operations for the Rabin-Williams
digital signature algorithm. This could allow remote attackers to mount a
timing attack and retrieve the user's private key.

Affected Software/OS:
libcrypto++ on Debian Linux

Solution:
For the oldstable distribution (wheezy),
this problem has been fixed in version 5.6.1-6+deb7u1.

For the stable distribution (jessie), this problem has been fixed in
version 5.6.1-6+deb8u1.

For the testing distribution (stretch), this problem will be fixed
in version 5.6.1-7.

For the unstable distribution (sid), this problem has been fixed in
version 5.6.1-7.

We recommend that you upgrade your libcrypto++ packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-2141
BugTraq ID: 75467
http://www.securityfocus.com/bid/75467
Debian Security Information: DSA-3296 (Google Search)
http://www.debian.org/security/2015/dsa-3296
SuSE Security Announcement: openSUSE-SU-2015:1271 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-07/msg00047.html
CopyrightCopyright (c) 2015 Greenbone Networks GmbH http://greenbone.net

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.