LWN.net Logo

openssl: private key disclosure

Package(s):openssl CVE #(s):CVE-2011-4354
Created:January 16, 2012 Updated:January 18, 2012
Description: From the Debian advisory:

On 32-bit systems, the operations on NIST elliptic curves P-256 and P-384 are not correctly implemented, potentially leaking the private ECC key of a TLS server. (Regular RSA-based keys are not affected by this vulnerability.)

Alerts:
Debian DSA-2390-1 2012-01-15
Ubuntu USN-1357-1 2012-02-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds