Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal), a related issue to CVE-2003-0147.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PeerSec MatrixSSL私钥获得漏洞
Vulnerability Description
PeerSec MatrixSSL 1.1之前版本不执行RSA盲点,相关的攻击者可以通过确定使用(1)在Montgomery减少期间额外减少的数量,以及(2)不同整数乘法算法("Karatsuba"和常态)运用上时差的决定因素来获得服务器的私钥,该漏洞与CVE-2003-0147的问题有关。
CVSS Information
N/A
Vulnerability Type
N/A