oss-sec mailing list archives
Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations
From: Roman Drahtmueller <draht () schaltsekun de>
Date: Wed, 08 Jun 2016 21:52:51 +0200
Hi Marcus,
Hi, the openssl team usually announces those LOW issues together with the other issues during their semi regular advisories. (And usually as soon as these LOW CVE issues are getting added to git, a new advisory is not far away.)
The only low part here appears to be the number of samples needed for a full recovery. Are we sure that a "low" rating is justified? DSA is basically dead, until the constant time switch is flicked. The only countermeasure so far is turning it off. Thx, Roman. -- schaltsekun.de
Current thread:
- CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Solar Designer (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Gsunde Orangen (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Alex Gaynor (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Gsunde Orangen (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Marcus Meissner (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Roman Drahtmueller (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Roman Drahtmueller (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Billy Brumley (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Roman Drahtmueller (Jun 09)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Billy Brumley (Jun 09)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Alex Gaynor (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Gsunde Orangen (Jun 08)
- Re: CVE-2016-2178: OpenSSL DSA follows a non-constant time codepath for certain operations Billy Brumley (Jun 08)