Mandriva Linux Security Advisory – A flaw in how OpenSSL performed Montgomery multiplications was discovered %that could allow a local attacker to reconstruct RSA private keys by examining another user’s OpenSSL processes. Moritz Jodeit found that OpenSSL’s SSL_get_shared_ciphers() function did not correctly check the size of the buffer it was writing to. As a result, a remote attacker could exploit this to write one NULL byte past the end of the application’s cipher list buffer, which could possibly lead to a denial of service or the execution of arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59815/MDKSA-2007-193.txt
Source: https://packetstormsecurity.com/files/59815/Mandriva-Linux-Security-Advisory-2007.193.html

