漏洞信息详情
OpenSSL错误版本数据库旁路攻击法漏洞
- CNNVD编号:CNNVD-200303-076
- 危害等级: 高危
- CVE编号:
CVE-2003-0131
- 漏洞类型:
设计错误
- 发布时间:
2003-03-24
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
openssl - 漏洞来源:
Discovery credited… -
漏洞简介
OpenSSL 0.9.6i及其更早版本以及0.9.7和0.9.7a版本的SSL和TLS组件存在漏洞。远程攻击者可以借助改进的Bleichenbacher攻击执行未认证RSA私钥操作,该攻击使用了大量PKCS #1 v1.5填充的SSL或TLS连接,可能导致OpenSSL泄露密文和相关纯文本之间的消息,也称为“Klima-Pokorny-Rosa attack”。
漏洞公告
It is reported that certain versions of Computer Associates eTrust Security Command Center are prone to this vulnerability. Customers are advised to contact the vendor for further information pertaining to obtaining and applying appropriate updates.
SGI have released an advisory (20030501-01-I) which contains a fix to address this issue.
SGI have released an advisory (20030501-01-I), which contains fix information to address this issue.
Hewlett-Packard have released an advisory (HPSBUX0304-0255 rev. 2) which contains fix information to address this issue.
Sorcerer Linux has released an advisory. Affected users are advised to issue the following commands to update the system:
augur synch && augur update
Gentoo has released openssl-0.9.6i-r2 which addresses this issue. Users are advised to upgrade by performing the following commands:
emerge sync
emerge openssl
emerge clean
NetBSD has made a source tree fix available, and has addressed this issue in NetBSD advisory 2003-007. See referenced advisory for additional details.
Trustix has released advisory 2003-0013 to address this issue.
Red Hat has released an advisory (RHSA-2003:101-01). Information about obtaining and applying fixes are available in the referenced advisory.
This issue is addressed in MacOS X 10.2.5. This update can be applied via the Software Update pane in System Preferences. Releases prior to 10.2.5 shipped with a vulnerable version of OpenSSL.
Debian has released a security advisory (DSA 288-1) containing fixes which address this and other issues. Further information regarding how to obtain and apply fixes can be found in the attached advisory.
F5 has released a patch which address this issue in their vulnerable products. A patch and further information can be obtained from the following location:
http://tech.f5.com/home/bigip/solutions/security/sol2379.html
GNU Transport Security Layer Library 0.8.5 has been made available which addresses this issue.
Ingrian Networks has reported that some products may be affected by this vulnerability. Users are advised to contact their vendor representitives or visit the
http://www.ingrian.com/support/ webpage.
Mirapoint has reported that various products may be affected by this vulnerability. A patch (D3_SSL) is available which addresses this issue and can be obtained by visiting the
http://support.mirapoint.com/ webpage.
HP has released SSL updates for OpenVMS systems. Please see the attached HP OpenVMS advisory (SSRT3499, SSRT3518) for details on obtaining and applying fixes. HP has also released an advisory for Tru64 UNIX systems that contains details about obtaining and applying patches. Please see advisory SSRT3499, SSRT3518 (Tru64) for further information.
SCO has released CSSA-2003-SCO.29 to address this and other issues in gwxlibs components for OpenServer. Please see CSSA-2003-SCO.29 for more details on obtaining and applying fixes.
Oracle has released an advisory and patches to address this issue. User are advised to obtain patches from the Oracle metalink site listed in references.
Fixes available:
Sun Cobalt RaQ 4
-
Sun RaQ4-All-Security-2.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-All-Security-2.0.
1-16343.pkg
Sun Cobalt RaQ 550
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security-
0.0.1-16343.pkg
Sun Cobalt RaQ XTR
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security-
0.0.1-16343.pkg -
Sun RaQXTR-All-Security-1.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security-
1.0.1-16343.pkg
Sun Cobalt Qube 3
-
Sun Qube3-All-Security-4.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0
.1-16343.pkg
GNU Transport Layer Security Library 0.8 .0
-
GNU gnutls-0.8.5.tar.gz
http://www.gnu.org/software/gnutls/download.html
GNU Transport Layer Security Library 0.8.1
-
GNU gnutls-0.8.5.tar.gz
http://www.gnu.org/software/gnutls/download.html
GNU Transport Layer Security Library 0.8.2
-
GNU gnutls-0.8.5.tar.gz
http://www.gnu.org/software/gnutls/download.html
GNU Transport Layer Security Library 0.8.3
-
GNU gnutls-0.8.5.tar.gz
http://www.gnu.org/software/gnutls/download.html
GNU Transport Layer Security Library 0.8.4
-
GNU gnutls-0.8.5.tar.gz
http://www.gnu.org/software/gnutls/download.html
OpenSSL Project OpenSSL 0.9.6 d
-
OpenSSL Project openssl-0.9.6j.tar.gz
http://www.openssl.org/source/openssl-0.9.6j.tar.gz
OpenSSL Project OpenSSL 0.9.6 c
-
Conectiva openssl-0.9.6c-2U80_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-0.9.6c-2U80_5cl.i38
6.rpm -
Conectiva openssl-devel-0.9.6c-2U80_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-0.9.6c-2U80_5
cl.i386.rpm -
Conectiva openssl-devel-static-0.9.6c-2U80_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-static-0.9.6c
-2U80_5cl.i386.rpm -
Conectiva openssl-doc-0.9.6c-2U80_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-doc-0.9.6c-2U80_5cl
.i386.rpm -
Conectiva openssl-progs-0.9.6c-2U80_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-progs-0.9.6c-2U80_5
cl.i386.rpm -
Debian libssl-dev_0.9.6c-0.potato.6_alpha.debDebian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-0.potato.6_alpha.deb -
Debian libssl-dev_0.9.6c-0.potato.6_arm.debDebian GNU/Linux 2.2 (potato)
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-0.potato.6_arm.deb -
Debian libssl-dev_0.9.6c-0.potato.6_i386.debDebian GNU/Linux 2.2 (potato)
http://security.debian
参考网址
来源:US-CERT Vulnerability Note: VU#888801
名称: VU#888801
链接:http://www.kb.cert.org/vuls/id/888801
来源: BID
名称: 7148
链接:http://www.securityfocus.com/bid/7148
来源: BUGTRAQ
名称: 20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104811162730834&w=2
来源: XF
名称: ssl-premaster-information-leak(11586)
链接:http://xforce.iss.net/xforce/xfdb/11586
来源: REDHAT
名称: RHSA-2003:102
链接:http://www.redhat.com/support/errata/RHSA-2003-102.html
来源: REDHAT
名称: RHSA-2003:101
链接:http://www.redhat.com/support/errata/RHSA-2003-101.html
来源: www.openssl.org
链接:http://www.openssl.org/news/secadv_20030319.txt
来源: SUSE
名称: SuSE-SA:2003:024
链接:http://www.novell.com/linux/security/advisories/2003_024_openssl.html
来源: www.linuxsecurity.com
链接:http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html
来源: DEBIAN
名称: DSA-288
链接:http://www.debian.org/security/2003/dsa-288
来源: lists.apple.com
链接:http://lists.apple.com/mhonarc/security-announce/msg00028.html
来源: eprint.iacr.org
链接:http://eprint.iacr.org/2003/052/
来源: SGI
名称: 20030501-01-I
链接:ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I
来源: NETBSD
名称: NetBSD-SA2003-007
链接:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc
来源: SUSE
名称: SuSE-SA:2003:024
链接:http://www.suse.de/de/security/2003_024_openssl.html
来源: BUGTRAQ
名称: 20030327 Immunix Secured OS 7+ openssl update
链接:http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded
来源: OPENPKG
名称: OpenPKG-SA-2003.026
链接:http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html
来源: MANDRAKE
名称: MDKSA-2003:035
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:035
来源: GENTOO
名称: GLSA-200303-20
链接:http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml
来源: TRUSTIX
名称: 2003-0013
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104878215721135&w=2
来源: BUGTRAQ
名称: 20030324 GLSA: openssl (200303-20)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104852637112330&w=2
来源: CONECTIVA
名称: CLA-2003:625
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625
来源: CALDERA
名称: CSSA-2003-014.0
链接:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt
来源: US Government Resource: oval:org.mitre.oval:def:461
名称: oval:org.mitre.oval:def:461
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461