Language Selection

English French German Italian Portuguese Spanish

OpenSSL Issues Fix

Filed under
Software
Security

The OpenSSL server has been patched to repair a critical security glitch that could be exploited in remote code execution attacks.

OpenSSL is a toolkit that implements Secure Sockets Layer and Transport Layer Security protocols, as well as a full strength, general purpose cryptography library.

The race condition flaw was found in the OpenSSL TLS server extension parsing code, affecting some multithreaded OpenSSL applications. Researchers at Red Hat Security, which relies on OpenSSL for an array of Red Hat Enterprise Linux products, warned in an advisory that under certain conditions, attackers could exploit the vulnerability by triggering a race condition that could cause the OpenSSL application to crash, or enable them to launch of a malicious attack.

The vulnerability, which Red Hat Security researchers ranked as "important" on their Common Vulnerability Scoring System, affects all versions of the OpenSSL supporting TLS extensions, including OpenSSL 0.9.8f through 0.9.8o, 1.0.0 and 1.0.0a.

rest here




More in Tux Machines

User’s Review On Linux Lite 3.0 – Simple, Fast & Free Linux Desktop

Linux Lite 3.0 is the recently released free operating system based on the Ubuntu LTS (Long Term Support) and hence you can be assured that you’ll get support for the next 5 years. Linux Lite 3.0 offers a complete out of the box experience and it is lightweight, easy and simple to install. One of the main aspects that is being lauded by experts and everyday Linux users is the compactness with which Linux Lite 3.0 has been released. This means you can install Linux Lite and start working with it in less than few minutes. Read more

Series on GNOME Shell

SUSE Leftovers