|
|
| |
|
| |
openssl: information leak
| Package(s): | openssl |
CVE #(s): | CVE-2010-1633
|
| Created: | June 15, 2010 |
Updated: | June 16, 2010 |
| Description: |
From the CVE entry:
RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors. NOTE: some of these details are obtained from third party information. |
| Alerts: |
|
( Log in to post comments)
|
|
|