CVE-2011-4108

Priority
Medium
Description
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f
performs a MAC check only if certain padding is valid, which makes it
easier for remote attackers to recover plaintext via a padding oracle
attack.
References
Assigned-to
sbeattie
Package
Upstream:released (0.9.8s)
Ubuntu 12.04 LTS (Precise Pangolin):released (0.9.8o-7ubuntu3.1)
Package
Upstream:released (0.9.8s,1.0.0f)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (1.0.0g-1ubuntu1)
More Information

Updated: 2016-03-23 03:39:02 UTC (commit 10817)