Oval Definition:oval:org.mitre.oval:def:461
Revision Date:2007-04-25Version:20
Title:Klima-Pokorny-Rosa Attack Vulnerability
Description:The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0131
Platform(s):Red Hat Linux 9
Product(s):OpenSSL
Definition Synopsis
  • Red Hat 9 is installed
  • AND ix86 architecture
  • AND affected version of SSL and TLS components for OpenSSL
  • openssl version is less than 0.9.7a-5
  • OR openssl-devel version is less than 0.9.7a-5
  • OR openssl-perl version is less than 0.9.7a-5
  • OR openssl096 version is less than 0.9.6-17
  • OR openssl096b version is less than 0.9.6b-6
  • BACK