Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 05:27:14 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1646409827&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0609-advisories%2FMDKSA-2006-161.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1646409827.1338182834.1338182834.1338182834.1%3B%2B__utmz%3D32867617.1338182834.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Mandriva Linux Security Advisory 2006.161 http://packetstormsecurity.org/files/49782/MDKSA-2006-161.txt http://packetstormsecurity.org/files/49782/MDKSA-2006-161.txt http://packetstormsecurity.org/files/49782/Mandriva-Linux-Security-Advisory-2006.161.html Thu, 07 Sep 2006 09:27:43 GMT Mandriva Linux Security Advisory MDKSA-2006-161 - Daniel Bleichenbacher recently described an attack on PKCS #1 version 1.5 signatures where an RSA key with a small exponent used could be vulnerable to forgery of a PKCS #1 version 1.5 signature signed by that key. Any software using OpenSSL to verify X.509 certificates is potentially vulnerable to this issue, as well as any other use of PKCS #1 version 1.5, including software uses OpenSSL for SSL or TLS.