Jump to content

OpenSSL patch fixes 7 vulnerabilities


Recommended Posts

http://cdn.mos.techradar.com/art/internet/heartbleed_padlock-470-75.jpg

Good news for those who fear being victims of any OpenSSL vulnerability. Since the discovery of the Heartbleed bug, security experts are pouring over its source code, in a bid to tidy up what could be described as a messy coding chaos.

And the first patches have followed swiftly. The OpenSSL open source project has issued a security patch that aims to fix 7 vulnerabilities, 2 of which have been deemed critical by the SAMS Internet Storm Center.

The first one is a so-called man-in-the-middle flaw, using a OpenSSL exploit to tamper with traffic between clients and servers.

It was discovered by Japanese researcher Masashi Kikuchi from security company Lepidum and has been around for over 16 years, since the very inception of OpenSSL.

Kikuchi blames the insufficient number of code reviews as well as the lack of experience of reviewers for the time it took to unearth this vulnerability.

Another critical flaw was identified six weeks ago and is classified as a "Datagram Transport Layer Security (DTLS) invalid fragment vulnerability", which is a buffer overrun attack, allowing an arbitrary code to be executed on the compromised host.

http://rss.feedsportal.com/c/669/f/415085/s/3b3b217b/sc/15/mf.gif


http://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/1/rc.img
http://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/2/rc.img
http://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/3/rc.img

http://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/a2.imghttp://pi.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/a2t.imghttp://feeds.feedburner.com/~r/techradar/software-news/~4/VkJP9TQ0SKk
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...