/plushcap/analysis/cloudflare/yet-another-padding-oracle-in-openssl-cbc-ciphersuites

Yet Another Padding Oracle in OpenSSL CBC Ciphersuites

What's this blog post about?

A new vulnerability has been discovered in OpenSSL/LibreSSL, specifically a padding oracle in CBC mode decryption. This issue is similar to the Lucky13 vulnerability and was found using TLS-Attacker tool developed by Juraj Somorovsky. The vulnerability affects servers with AES-NI instructions and can be exploited to recover at least 16 bytes of data sent repeatedly just before attacker-controlled data, such as HTTP Cookies. CloudFlare websites are protected from this vulnerability, but customers supporting only AES-CBC should upgrade their systems as soon as possible.

Company
Cloudflare

Date published
May 4, 2016

Author(s)
Filippo Valsorda

Word count
2239

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.