IBM Information for VU#888801
SSL/TLS implementations disclose side channel information via PKCS #1 v1.5 version number extension
- Vendor Information Help Date Notified: 18 Apr 2003
- Statement Date:
- Date Updated: 17 Jun 2003
The AIX operating system does not ship with SSL. However, SSL is available for installation on AIX from the Linux Affinity Toolbox.
The Linux Affinity Toolbox contains OpenSSL 0.9.6g-3 which is not vulnerable to the issues discussed in CERT Vulnerability Note VU#888801 and any advisories which follow.
Users using an earlier version of OpenSSL should download the most recent version as soon as possible.
The Linux Affinity Toolbox is available at:
This software is offered on an "as-is" and is unwarranted.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.