oss-sec mailing list archives

Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations


From: Billy Brumley <bbrumley () gmail com>
Date: Wed, 8 Jun 2016 19:13:42 +0300

I assume the OpenSSL team considers this vulnerability to be LOW severity:
https://www.openssl.org/policies/secpolicy.html

Yes this is correct. BBB


Current thread: