Red Hat Inc. Information for VU#888801

SSL/TLS implementations disclose side channel information via PKCS #1 v1.5 version number extension

Status

Affected

Vendor Statement

Various Red Hat products have shipped with OpenSSL packages vulnerable to this issue. Updated OpenSSL packages that contain a backported security patch to protect against this vulnerability are available along with our advisories at the URLs below. Users of the Red Hat Network can update their systems using the 'up2date' tool.
Red Hat Linux:

Red Hat Enterprise Linux:
Red Hat Stronghold Web Server 4 (Cross platform):
Red Hat Stronghold Web Server 3:
    http://rhn.redhat.com/errata/RHSA-2003-117.html

    Vendor Information

    The vendor has not provided us with any further information regarding this vulnerability.

    Vendor References

    None

    Addendum

    The CERT/CC has no additional comments at this time.

    If you have feedback, comments, or additional information about this vulnerability, please send us email.