about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , OpenSSL Montgomery Exponentiation Side-Channel Local Information Disclosure Vulnerability


Title OpenSSL Montgomery Exponentiation Side-Channel Local Information Disclosure Vulnerability
Published 2007-08-01-12:00AM
Updated 2008-01-23-11:28PM
Class Design Error
CVE   CVE-2007-3108
Remote  No
Local  Yes
Credit  The vendor disclosed this issue.
Vulnerable  VMWare ESX Server 3.0.2
VMWare ESX Server 3.0.1
VMWare ESX Server 2.5.5 patch 2
VMWare ESX Server 2.5.4 patch 13
Ubuntu Ubuntu Linux 7.04 sparc
Ubuntu Ubuntu Linux 7.04 powerpc
Ubuntu Ubuntu Linux 7.04 i386
Ubuntu Ubuntu Linux 7.04 amd64
Ubuntu Ubuntu Linux 6.10 sparc
Ubuntu Ubuntu Linux 6.10 powerpc
Ubuntu Ubuntu Linux 6.10 i386
Ubuntu Ubuntu Linux 6.10 amd64
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Turbolinux Turbolinux Server 10.0
Turbolinux Turbolinux Server 10.0.0 x64
TurboLinux Personal
TurboLinux Multimedia
Turbolinux FUJI 0
Turbolinux Appliance Server Workgroup Edition 1.0
Turbolinux Appliance Server Hosting Edition 1.0
Turbolinux Appliance Server 1.0 Workgroup Edition
Turbolinux Appliance Server 1.0 Hosting Edition
Turbolinux Appliance Server 2.0
TransSoft Broker FTP Server 8.0
rPath rPath Linux 1
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux WS 2.1 IA64
RedHat Enterprise Linux WS 2.1
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux ES 2.1 IA64
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux Desktop Workstation 5 client
RedHat Enterprise Linux Desktop 5 client
RedHat Enterprise Linux AS 4
RedHat Enterprise Linux AS 3
RedHat Enterprise Linux AS 2.1 IA64
RedHat Enterprise Linux AS 2.1
RedHat Enterprise Linux 5 server
RedHat Desktop 4.0
RedHat Desktop 3.0
RedHat Advanced Workstation for the Itanium Processor 2.1 IA64
RedHat Advanced Workstation for the Itanium Processor 2.1
OpenSSL Project OpenSSL 0.9.8 e
OpenSSL Project OpenSSL 0.9.8 d
OpenSSL Project OpenSSL 0.9.8 c
OpenSSL Project OpenSSL 0.9.8 b
OpenSSL Project OpenSSL 0.9.8 a
OpenSSL Project OpenSSL 0.9.8
Gentoo Linux
OpenBSD OpenBSD 4.0
MandrakeSoft Multi Network Firewall 2.0
MandrakeSoft Linux Mandrake 2007.1 x86_64
MandrakeSoft Linux Mandrake 2007.1
MandrakeSoft Linux Mandrake 2007.0 x86_64
MandrakeSoft Linux Mandrake 2007.0
MandrakeSoft Corporate Server 4.0 x86_64
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 4.0
Gentoo Linux
Foresight Linux Foresight Linux 1.1
Blue Coat Systems SGME
Blue Coat Systems SGClient 0
Blue Coat Systems ProxySG 0
Blue Coat Systems ProxyAV
Blue Coat Systems Blue Coat Reporter 7.1.2
Blue Coat Systems Blue Coat Reporter 7.1.1 .1
Blue Coat Systems Blue Coat Reporter 7.0
Avaya EMMC 1.021
Avaya EMMC 1.017
Avaya Communication Manager 3.0
Avaya Communication Manager Server DEFINITY Server SI/CS
Avaya Communication Manager Server DEFINITY Server SI/CS
Avaya Communication Manager Server S8100
Avaya Communication Manager Server S8100
Avaya Communication Manager Server S8300
Avaya Communication Manager Server S8300
Avaya Communication Manager Server S8500
Avaya Communication Manager Server S8500
Avaya Communication Manager Server S8700
Avaya Communication Manager Server S8700
Avaya CCS 3.1
Avaya CCS 3.0
Avaya CCS 2.0
Avaya AES 3.1.4
Not Vulnerable  
Code  Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: content@securitydot.net.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 23:55:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.xxwxx. Sexy ftv 654321 news for c I+agree+wi Clisteri www.qiansh Free3gp news for c php-nuke 2 vidio anak Www.Sexwal Kiran vidoporno index.php? Xxxmove www.j131.c Searching news for c vidoporno ms05-43 Www.sex vi solaris2.5 saxyaishwa hindi sexy Sexygirls. seks bebas IBM AIX www.sexmov http//cydn windowss x Movie Play train from Nakedfatgi Baba t167t Www.Arabsx bangbus sexy arabe 200 /compo Cartoonpor maxcpm.inf ZSNES php-nuke 2 Www.sexabg www.xkltea us robotic mod_fastcg 200 //inde xhkdw.com