Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 20 Oct 2011 12:58:11 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: oss-security@...ts.openwall.com
Subject: PR attack against XML Encryption

A German university has released a press release, alleging a
vulnerability in the W3C XML Encryption standard.  Apparently, error
reporting from existing implementations can be used as an oracle to
recover information from messages encrypted in CBC mode.

Details have not been published, as far as I know.  Does anybody know
more?

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.