About the openssl hole

From: Geir Råness (pulz@pulz.no)
Date: 07/30/02


From: Geir Råness <pulz@pulz.no>
To: <freebsd-security@freebsd.org>
Date: Tue, 30 Jul 2002 15:43:50 +0200

Shuld we start to edit the openssl port (I have emailed the maninter to update to 96.e, "or supply the patch from openssl" in the /usr/ports/security/openssl), or shuld we wait for an patch from the freebsd team ?

If you look at bugtrac there are already romours about exploits flying around now.

Read the Advisory from openssl here
http://www.openssl.org/news/secadv_20020730.txt

Best Regards
Geir Råness

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • RE: FreeBSD Security Advisory FreeBSD-SA-06:23.openssl
    ... The description of CVE-2006-3738 in the advisory from openssl.org ... Subject: FreeBSD Security Advisory FreeBSD-SA-06:23.openssl ... FreeBSD includes software from the OpenSSL Project. ... Applications which perform public key operations using untrusted keys may be ...
    (FreeBSD-Security)
  • OpenSSL Security Altert - Remote Buffer Overflows
    ... OpenSSL Security Advisory ... This advisory consists of two independent advisories, merged, and is ... diff -u -r1.618.2.158 CHANGES ... retrieving revision 1.20.2.4 ...
    (Bugtraq)
  • [OpenPKG-SA-2002.008] OpenPKG Security Advisory (openssl)
    ... According to an official security advisory from the OpenSSL team, ... $ ftp ftp.openpkg.org ...
    (Bugtraq)
  • [Full-Disclosure] GLSA: openssl (200303-15)
    ... "Researchers have discovered a timing attack on RSA keys, ... OpenSSL is generally vulnerable, unless RSA blinding has been turned ... The enclosed patch switches blinding on by default. ... Read the full advisory at ...
    (Full-Disclosure)
  • GLSA: openssl (200303-15)
    ... "Researchers have discovered a timing attack on RSA keys, ... OpenSSL is generally vulnerable, unless RSA blinding has been turned ... The enclosed patch switches blinding on by default. ... Read the full advisory at ...
    (Bugtraq)