oss-sec mailing list archives

Re: CVE request: openssl timing attack


From: Solar Designer <solar () openwall com>
Date: Sun, 10 Jul 2011 10:05:08 +0400

On Wed, Jul 06, 2011 at 12:51:39PM +0200, Tomas Hoger wrote:
We have bugzilla (as usual, use CVE as a bug id), but not too useful
for other distros, as it only says we're not affected.  All EC crypto is
one of the "patent or otherwise encumbered" code pieces that are removed
and not compiled in.

http://pkgs.fedoraproject.org/gitweb/?p=openssl.git;a=blob;f=hobble-openssl;h=a8be844f6ba7654b5738ae0e27e192a38797bd74;hb=master

Oh, I did not realize this was the case.  Looks like we don't compile
this stuff in either - we have "no-idea no-mdc2 no-rc5 no-ec no-ecdh
no-ecdsa" on the ./Configure line.

Thanks,

Alexander


Current thread: