USN-8769-1: phpseclib vulnerability
Ubuntu patches phpseclib non-constant-time padding validation enabling remote padding oracle timing attacks against AES-CBC.
Ubuntu security notice USN-8769-1 addresses a vulnerability in phpseclib where padding validation was not performed in constant time when using AES in CBC mode. A remote attacker could leverage this timing side channel to conduct a padding oracle attack and decrypt sensitive information. Users are advised to update the phpseclib package.
- Non-constant-time padding checks in AES-CBC mode expose a timing oracle
- Remote attackers could decrypt sensitive data via padding oracle attack
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.
This source does not provide full text. Read it at ubuntu.com.