Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20110710060508.GB8303@openwall.com>
Date: Sun, 10 Jul 2011 10:05:08 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: openssl timing attack

On Wed, Jul 06, 2011 at 12:51:39PM +0200, Tomas Hoger wrote:
> We have bugzilla (as usual, use CVE as a bug id), but not too useful
> for other distros, as it only says we're not affected.  All EC crypto is
> one of the "patent or otherwise encumbered" code pieces that are removed
> and not compiled in.
> 
> http://pkgs.fedoraproject.org/gitweb/?p=openssl.git;a=blob;f=hobble-openssl;h=a8be844f6ba7654b5738ae0e27e192a38797bd74;hb=master

Oh, I did not realize this was the case.  Looks like we don't compile
this stuff in either - we have "no-idea no-mdc2 no-rc5 no-ec no-ecdh
no-ecdsa" on the ./Configure line.

Thanks,

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.