Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OpenSSL Timing Attack RSA Private Key Information Disclosure Vulnerability

A side-channel attack in the OpenSSL implementation has been published in a recent paper that may ultimately result in an active adversary gaining the RSA private key of a target server. The attack involves analysis of the timing of certain operations during client-server session key negotiation. Through this attack, it may be possible for a malicious client to discover the RSA private key of a server using the vulnerable software.







 

Privacy Statement
Copyright 2008, SecurityFocus