由 thunderbird 在 03-07-2003 11:14 发表:
Linux 更新信息……求翻择
先谢谢了,大概什么意思啊?
Summary:
Updated OpenSSL packages fix timing attack
Updated OpenSSL packages are available that fix a potential timing-based
attack.
Description:
OpenSSL is a commercial-grade, full-featured, and open source toolkit that
implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer
Security (TLS v1) protocols as well as a full-strength general purpose
cryptography library.
In a paper, Brice Canvel, Alain Hiltgen, Serge Vaudenay, and Martin
Vuagnoux describe and demonstrate a timing-based attack on CBC ciphersuites
in SSL and TLS. An active attacker may be able to use timing observations
to distinguish between two different error cases: cipher padding errors and
MAC verification errors. Over multiple connections this can leak
sufficient information to make it possible to retrieve the plaintext of a
common, fixed block.
In order for an attack to be sucessful, an attacker must be able to act as
a man-in-the-middle to intercept and modify multiple connections, which all
involve a common fixed plaintext block (such as a password), and have good
network conditions that allow small changes in timing to be reliably
observed.
These erratum packages contain a patch provided by the OpenSSL group that
corrects this vulnerability.
Because server applications are affected by these vulnerabilities, we
advise users to restart all services that use OpenSSL functionality or
alternatively reboot their systems after installing these updates.
References:
http://lasecwww.epfl.ch/pub/lasec/doc/Vau02a.ps
由 Snoopy 在 03-07-2003 12:36 发表:
是不是关于加密的啊????大家知道贴文章啊,我也想知道
And then in the evening light, when the bars of freedom fall
I watch the two of you in the shadows on the wall
How in the darkness steals some of the choices from my hand
Then will I begin to under
由 david yang 在 03-07-2003 19:32 发表:
Re: Linux 更新信息……求翻择
> quote:
>
> * * *
>
> 最初由 thunderbird 发布
>
> **先谢谢了,大概什么意思啊?
>
> These erratum packages contain a patch provided by the OpenSSL group that
>
> corrects this vulnerability.
>
>
>
>
>
> because server applications are affected by these vulnerabilities, we
>
> advise users to restart all services that use OpenSSL functionali **