Red Hat Inc. Information for VU#888801
SSL/TLS implementations disclose side channel information via PKCS #1 v1.5 version number extension
- Vendor Information Help Date Notified: 18 Apr 2003
- Statement Date:
- Date Updated: 18 Apr 2003
Various Red Hat products have shipped with OpenSSL packages vulnerable to this issue. Updated OpenSSL packages that contain a backported security patch to protect against this vulnerability are available along with our advisories at the URLs below. Users of the Red Hat Network can update their systems using the 'up2date' tool.
Red Hat Linux:
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.