Language Selection

English French German Italian Portuguese Spanish

OpenSSL Issues Fix

Filed under
Software
Security

The OpenSSL server has been patched to repair a critical security glitch that could be exploited in remote code execution attacks.

OpenSSL is a toolkit that implements Secure Sockets Layer and Transport Layer Security protocols, as well as a full strength, general purpose cryptography library.

The race condition flaw was found in the OpenSSL TLS server extension parsing code, affecting some multithreaded OpenSSL applications. Researchers at Red Hat Security, which relies on OpenSSL for an array of Red Hat Enterprise Linux products, warned in an advisory that under certain conditions, attackers could exploit the vulnerability by triggering a race condition that could cause the OpenSSL application to crash, or enable them to launch of a malicious attack.

The vulnerability, which Red Hat Security researchers ranked as "important" on their Common Vulnerability Scoring System, affects all versions of the OpenSSL supporting TLS extensions, including OpenSSL 0.9.8f through 0.9.8o, 1.0.0 and 1.0.0a.

rest here




More in Tux Machines

Bill Gates Inadvertently Shows Off Ubuntu on His Facebook Page

Bill Gates is much more involved in philanthropy than Microsoft these days and he's done some great work regarding the eradications of certain diseases and to improve the quality of life in a number of third world countries. He's also inadvertently promoted Ubuntu, which is a Linux system. Read more

Major Release LibreOffice 4.4 Announced

The Document Foundation today announced the latest and "most beautiful" LibreOffice ever. LibreOffice 4.4 is the ninth major release for the project and brings with it lots of design and functionality improvements. Redesigned toolbars, menus, status bars, rulers and new theme selector are among the goodies for users. Michael Meeks said today that this release not only improves the visible features but also the foundations underneath. Read more

Sphinx: An outstanding open source documentation platform

Sphinx is a free, open source project written in Python and, not surprisingly, is really well suited for documenting Python projects. Now, before you harrumph “Meh, I code in which isn’t at all like Python!” be aware that Sphinx supports several other languages (C and C++ support is in development). Read more

today's leftovers