OpenSSL CMS and PKCS #7 contain a weakness that may allow a remote attacker to send a saturation of ciphertext to be decrypted, then uses the results of the decryption to select subsequent ciphertexts in a Million Message Attack (MMA). This may allow the attacker to decrypt certain operations.
Classification
Location:
Context Dependent
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Upgrade to version 1.0.0h or 0.9.8u or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.