Vulnerability Description
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal), a related issue to CVE-2003-0147.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Peersec Networks | Matrixssl | <= 1.0 |
References
FAQ
What is CVE-2004-2682?
CVE-2004-2682 is a vulnerability with a CVSS score of 5.8 (MEDIUM). PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the num...
How severe is CVE-2004-2682?
CVE-2004-2682 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2682?
Check the references section above for vendor advisories and patch information. Affected products include: Peersec Networks Matrixssl.