REDHAT-BUG-1119475: Medium severity openjdk security vulnerability
It was discovered that the RSA algorithm in the OpenJDK Security component did not sufficiently preform "blinding" while performing operations using private keys. An attacker able to measure timing differences of those operations could possibly leak information about the keys used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1119475?
The severity of REDHAT-BUG-1119475 is considered high due to potential key leakage via timing attacks.
How do I fix REDHAT-BUG-1119475?
To fix REDHAT-BUG-1119475, you should update to the latest patched version of OpenJDK Security.
What causes the vulnerability REDHAT-BUG-1119475?
REDHAT-BUG-1119475 is caused by insufficient blinding in the RSA algorithm which exposes private key operations to timing attacks.
Who is affected by REDHAT-BUG-1119475?
Users of the OpenJDK Security component are affected by REDHAT-BUG-1119475.
What can attackers do with the vulnerability REDHAT-BUG-1119475?
Attackers can exploit REDHAT-BUG-1119475 to possibly leak confidential information about RSA private keys through timing differences.