CVE-2008-7128
Publication date 31 August 2009
Last updated 24 July 2024
Ubuntu priority
Description
The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors.