The version of OpenSSL software shipped with SSC and SDX releases built prior to March 6, 2003, do not perform a MAC checksum calculation on packets which contain incorrect block cipher padding. The timing difference between reporting incorrect padding vs. MAC checksum verification errors can provide valuable information to active attacks against certain encryption algorithms. More details can be found at http://www.openssl.org/news/secadv_20030219.txt .
All SDX and SSC software built on or after March 6, 2003, will perform the MAC checksum calculation on all packets, including packets with incorrect block cipher padding. This minimizes the amount of information leaked, since error reporting will take the same amount of time for both error types.
Customers should install one of the following releases of SSC or SDX: