Language Selection

English French German Italian Portuguese Spanish

OpenSSL Issues Fix

Filed under
Software
Security

The OpenSSL server has been patched to repair a critical security glitch that could be exploited in remote code execution attacks.

OpenSSL is a toolkit that implements Secure Sockets Layer and Transport Layer Security protocols, as well as a full strength, general purpose cryptography library.

The race condition flaw was found in the OpenSSL TLS server extension parsing code, affecting some multithreaded OpenSSL applications. Researchers at Red Hat Security, which relies on OpenSSL for an array of Red Hat Enterprise Linux products, warned in an advisory that under certain conditions, attackers could exploit the vulnerability by triggering a race condition that could cause the OpenSSL application to crash, or enable them to launch of a malicious attack.

The vulnerability, which Red Hat Security researchers ranked as "important" on their Common Vulnerability Scoring System, affects all versions of the OpenSSL supporting TLS extensions, including OpenSSL 0.9.8f through 0.9.8o, 1.0.0 and 1.0.0a.

rest here




More in Tux Machines

Today in Techrights

Linux and Graphics

today's howtos

Ubuntu 16.04.2 LTS Delayed Until February 2, Will Bring Linux 4.8, Newer Mesa

If you've been waiting to upgrade your Ubuntu 16.04 LTS (Xenial Xerus) operating system to the 16.04.2 point release, which should have hit the streets a couple of days ago, you'll have to wait until February 2. We hate to give you guys bad news, but Canonical's engineers are still working hard these days to port all the goodies from the Ubuntu 16.10 (Yakkety Yak) repositories to Ubuntu 16.04 LTS, which is a long-term supported version, until 2019. These include the Linux 4.8 kernel packages and an updated graphics stack based on a newer X.Org Server version and Mesa 3D Graphics Library. Read more