Description
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal), a related issue to CVE-2003-0147.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2004-2672 | PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal), a related issue to CVE-2003-0147. |
References
| Link | Providers |
|---|---|
| http://www.matrixssl.org/archives/000075.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T18:38:51.660Z
Reserved: 2007-07-05T00:00:00.000Z
Link: CVE-2004-2682
No data.
Status : Modified
Published: 2004-12-31T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-2682
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD