CVE-2008-7128 Information

Description

The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext which allows remote attackers to recover keys via unspecified vectors.

Reference

http://polarssl.org/?archive001c http://www.vupen.com/english/advisories/2008/0917/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41253

Share on: