LWN.net Logo

openssl: information leak

Package(s):openssl CVE #(s):CVE-2010-1633
Created:June 15, 2010 Updated:June 16, 2010
Description: From the CVE entry:

RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors. NOTE: some of these details are obtained from third party information.

Alerts:
Gentoo 201110-01 2011-10-09
Fedora FEDORA-2010-9574 2010-06-07
Fedora FEDORA-2010-9639 2010-06-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds