aboutsummaryrefslogtreecommitdiff
path: root/security/vuxml/vuln.xml
diff options
context:
space:
mode:
authorRoman Bogorodskiy <novel@FreeBSD.org>2006-09-13 18:39:37 +0000
committerRoman Bogorodskiy <novel@FreeBSD.org>2006-09-13 18:39:37 +0000
commited6242f1b337213782011864a27fb93e4dd57bde (patch)
treedd8184d85b11e977529275c743c3174928381b14 /security/vuxml/vuln.xml
parentf3b14481cbbb0bb6a5a1dbcdaf9fa00e5e062796 (diff)
Notes
Diffstat (limited to 'security/vuxml/vuln.xml')
-rw-r--r--security/vuxml/vuln.xml38
1 files changed, 1 insertions, 37 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index b1e8b5866b29..8f79da2fc62f 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -102,43 +102,7 @@ Note: Please add new entries to the beginning of this file.
</vuln>
<vuln vid="28ce7102-4039-11db-a838-00148584c7dd">
- <topic>gnutls -- Adaptive Chosen Ciphertext Attack</topic>
- <affects>
- <package>
- <name>gnutls</name>
- <range><lt>1.4.3</lt></range>
- </package>
- <package>
- <name>gnutls-devel</name>
- <range><le>1.5.0</le></range>
- </package>
- </affects>
- <description>
- <body xmlns="http://www.w3.org/1999/xhtml">
- <p>Simon Josefsson reports:</p>
- <blockquote cite="http://lists.gnupg.org/pipermail/gnutls-dev/2006-September/001203.html">
- <p><code>_gnutls_handshake_log ("PKCS #1 padding error");
- ret = GNUTLS_E_PKCS1_WRONG_PAD;</code></p>
- <p>Werner Koch points out that this error message may result
- in a vulnerability similar to Bleichenbacher's Crypto 98
- attack. It is not exactly the same situation --
- Bleichenbacher talks about PKCS#1 encryption (block type 1,
- uses random padding) where this deals with PKCS#1
- verification (block type 2, uses 0xFF padding) -- but at a
- glance, it appears to have similar consequences, but differ
- in the number of messages required to mount the attack.</p>
- </blockquote>
- </body>
- </description>
- <references>
- <url>http://lists.gnupg.org/pipermail/gnutls-dev/2006-September/001203.html</url>
- <url>http://www.bell-labs.com/user/bleichen/papers/pkcs.ps</url>
- </references>
- <dates>
- <discovery>2006-09-08</discovery>
- <entry>2006-09-09</entry>
- <modified>2006-09-13</modified>
- </dates>
+ <cancelled/>
</vuln>
<vuln vid="fffa9257-3c17-11db-86ab-00123ffe8333">