[关闭]
@ensis 2016-03-07T15:33:10.000000Z 字数 383 阅读 1366

CVE-2016-0800: DROWN ATTACK

cve


网页】【paper
Decrypting RSA with Obsolete and Weakened eNcryption
Conditions: SSLv2 is enabled or private key is used on other sslv2 enabled servers
Root cause: SSLv2 has no padding, unpadded RSA is malleable. 【cross-protocol Bleichenbacher padding oracle attack】

OpenSSL的另外两个实现问题使得这个漏洞影响更大:

添加新批注
在作者公开此批注前,只有你和作者可见。
回复批注