USN-3628-2: OpenSSL vulnerability
19 April 2018
OpenSSL could allow access to sensitve information.
- openssl - Secure Socket Layer (SSL) cryptographic library and tools
USN-3628-1 fixed a vulnerability in OpenSSL. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia
discovered that OpenSSL incorrectly handled RSA key generation. An attacker could possibly
use this issue to perform a cache-timing attack and recover private RSA keys.