Website Security & Threat Management
Yet Another Padding Oracle in OpenSSL CBC Ciphersuites

Yet Another Padding Oracle in OpenSSL CBC Ciphersuites

5/4/2016 · Filippo Valsorda

What this post added

This post details a specific padding oracle vulnerability (CVE-2016-2107) found in OpenSSL's CBC mode cipher suites, which was a fix for a previous vulnerability (Lucky13). It explains the technical details of the vulnerability, how it exploits constant-time programming practices, and how Cloudflare engineers analyze and address such cryptographic weaknesses to maintain the security of its network and customer connections.

Read the original post ↗