CVE-2005-1797: Medium severity OpenSSL OpenSSL vulnerability
Published May 26, 2005
·Updated
The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES implementations.
Affected Software
28 affected components
OpenSSL OpenSSL=0.9.7-beta3
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.3
OpenSSL OpenSSL=0.9.7-beta2
OpenSSL OpenSSL=0.9.7c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.1c
OpenSSL OpenSSL=0.9.6
OpenSSL OpenSSL=0.9.6a
OpenSSL OpenSSL=0.9.4
OpenSSL OpenSSL=0.9.5a
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.6l
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.7d
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.6b
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.7-beta1
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6m
OpenSSL OpenSSL=0.9.2b
OpenSSL OpenSSL=0.9.5
Event History
May 26, 2005
CVE Published
04:00 AM
Jun 1, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1797?
CVE-2005-1797 has been classified as having a moderate severity level.
2
How do I fix CVE-2005-1797?
To fix CVE-2005-1797, you should upgrade to a patched version of OpenSSL that mitigates timing attacks.
3
What versions of OpenSSL are affected by CVE-2005-1797?
CVE-2005-1797 affects multiple versions of OpenSSL, including 0.9.1c through 0.9.7d.
4
What kind of attack does CVE-2005-1797 exploit?
CVE-2005-1797 exploits timing attacks specifically targeting the S-box lookups within AES implementations.
5
Is CVE-2005-1797 a local or remote vulnerability?
CVE-2005-1797 is a remote vulnerability that allows attackers to recover AES keys through network interactions.