critical openssl Patch

Kohler, Bernd Kohler at itc.rwth-aachen.de
Wed Jun 11 10:03:00 EDT 2014


Hi Scott,

did you already build - due to openssl - the Shibboleth Service Provider
today?

Ok, I don't want to start a bashing, just wanted to forward the information
about CVE-2011-4354 [1]:

"... in certain circumstances involving ECDH or ECDHE cipher suites, uses an
incorrect modular reduction algorithm in its implementation of the P-256 and
P-384 NIST elliptic curves, which allows remote attackers to obtain the
private key of a TLS server via multiple handshake attempts."

Sorry, I hope I didn't ruin you day.

Thx for your great work

Regards

Bernd

[1]
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4354




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5678 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20140611/de83b67f/attachment.bin 


More information about the users mailing list