CVE-2010-0928
Publication date 5 March 2010
Last updated 24 July 2024
Ubuntu priority
Description
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a “fault-based attack.”
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openssl | 10.04 LTS lucid | Ignored |
| 9.10 karmic | Ignored | |
| 9.04 jaunty | Ignored | |
| 8.10 intrepid | Ignored end of life, was needed | |
| 8.04 LTS hardy | Ignored | |
| 6.06 LTS dapper | Ignored |