Gentoo: stunnel Remote timing attack
Summary
- --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-24 - --------------------------------------------------------------------- FIXED VERSION : >=3.22-r2 (unstable: >=4.04)
- ---------------------------------------------------------------------
>From advisory:
"Researchers have discovered a timing attack on RSA keys, to which OpenSSL is generally vulnerable, unless RSA blinding has been turned on."
Read the full advisory at
SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/stunnel upgrade to stunnel-3.22-r2 (unstable: stunnel-4.04) as follows:
emerge sync emerge stunnel emerge clean
Resolution
References
Availability
Concerns
Background