Debian Security Advisory 3417-1

Discussion in 'News Aggregator' started by Packet Storm, 15 Dec 2015.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3417-1 - Tibor Jager, Jorg Schwenk, and Juraj Somorovsky, from Horst Gortz Institute for IT Security, published a paper in ESORICS 2015 where they describe an invalid curve attack in Bouncy Castle Crypto, a Java library for cryptography. An attacker is able to recover private Elliptic Curve keys from different applications, for example, TLS servers.

    Continue reading...
     

Share This Page

Loading...