oss-sec mailing list archives

PR attack against XML Encryption


From: Florian Weimer <fw () deneb enyo de>
Date: Thu, 20 Oct 2011 12:58:11 +0200

A German university has released a press release, alleging a
vulnerability in the W3C XML Encryption standard.  Apparently, error
reporting from existing implementations can be used as an oracle to
recover information from messages encrypted in CBC mode.

Details have not been published, as far as I know.  Does anybody know
more?


Current thread: