Re: [openssl-users] CVE-201-0737

2018-04-16 Thread Scott Neugroschl
On 16/04/18 0935PDT, Matt Caswell wrote: >On 16/04/18 16:59, Scott Neugroschl wrote: >> Hi, >> >> I'm trying to make sure I have grokked this advisory properly. >> >> The advisory says this is a cache timing side channel attack on key >> generation. So am I correct in assuming that a

Re: [openssl-users] CVE-201-0737

2018-04-16 Thread Matt Caswell
On 16/04/18 16:59, Scott Neugroschl wrote: > Hi, > > I'm trying to make sure I have grokked this advisory properly. > > The advisory says this is a cache timing side channel attack on key > generation. So am I correct in assuming that a potential attacker must > > 1) Already have access to

[openssl-users] CVE-201-0737

2018-04-16 Thread Scott Neugroschl
Hi, I'm trying to make sure I have grokked this advisory properly. The advisory says this is a cache timing side channel attack on key generation. So am I correct in assuming that a potential attacker must 1) Already have access to the system 2) Have sufficient privilege to be able to access