Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 214206 - net-libs/xyssl <0.9 Multiple vulnerabilities
Summary: net-libs/xyssl <0.9 Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://xyssl.org/?archive#001c
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-03-22 01:15 UTC by Robert Buchholz (RETIRED)
Modified: 2008-03-30 22:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-03-22 01:15:37 UTC
From 0.9 ChangeLog:
    * Fixes a critical denial-of-service with x.509 certificate verification:
      peer may cause xyssl to loop indefinitely by sending a cert. for which
      the PKCS#1 RSA signature check fails (bug reported by Benoit)
...
    * Modified ssl_parse_client_key_exchange() to protect against
      Daniel Bleichenbacher attack on PKCS#1 v1.5 padding, as well as
      the Klima-Pokorny-Rosa extension of Bleichenbacher's attack

See also http://www.frsirt.com/english/advisories/2008/0917
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-03-22 01:15:57 UTC
please bump
Comment 2 Lars Weiler (RETIRED) gentoo-dev 2008-03-29 23:38:11 UTC
Version bumped in CVS.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-03-30 22:17:30 UTC
Thanks, Lars.