Re: OpenSSL Vulnerability and OpenSSH

From: Markus Friedl (markus@openbsd.org)
Date: 09/23/02


Date: Mon, 23 Sep 2002 16:14:31 +0200
From: Markus Friedl <markus@openbsd.org>
To: nestler@speakeasy.net

On Mon, Sep 23, 2002 at 10:24:53AM +0200, Markus Friedl wrote:
> On Sat, Sep 21, 2002 at 09:43:48AM -0700, nestler@speakeasy.net wrote:
> > > On Fri, Sep 20, 2002 at 09:05:59AM -0400, Eric Maiwald wrote:
> > > > Does anyone
> > > > know if the same issues affecting OpenSSL on Apache will affect OpenSSL
> > > > when used with OpenSSH?
> > >
> > > yes.
> > >
> > > the "issues affecting OpenSSL on Apache" do not affect OpenSSH.
> > >
> > > OpenSSH does not use libssl (only libcrypto).
> >
> > You seem to imply that all of OpenSSL's problems are in libssl,
> > which is not the case.
>
> no. it does not. i just refer to "issues affecting OpenSSL on Apache".

oops, i forgot to add: you should still update the OpenSSL libcrypto
library, since it's not know how the ASN.1 bugs affect software using
libcrypto (and OpenSSH uses libcrypto).



Relevant Pages

  • RES: OpenSSL Vulnerability and OpenSSH
    ... applications using OpenSSL to provide SSL or TLS...", i did it (apache, ... i just refer to "issues affecting OpenSSL on Apache". ... since it's not know how the ASN.1 bugs affect software using ... libcrypto. ...
    (Vuln-Dev)
  • [Full-Disclosure] NetBSD Security Advisory 2003-005: RSA timing attack in OpenSSL code
    ... A timing attack has been discovered, which can be used against OpenSSL. ... low-latency access to the server - such as the local host, ... The following instructions describe how to upgrade your libcrypto ... Information about NetBSD and NetBSD security can be found at ...
    (Full-Disclosure)
  • NetBSD Security Advisory 2003-005: RSA timing attack in OpenSSL code
    ... A timing attack has been discovered, which can be used against OpenSSL. ... The attack allows remote recovery of private keys, ... low-latency access to the server - such as the local host, ... The following instructions describe how to upgrade your libcrypto ...
    (Bugtraq)
  • Re: Encryption
    ... you may already have OpenSSL and libcrypto. ... The library on Jazz excludes certain algorithms that were patent-encumbered at the time, although most or all of the patents have since expired. ... I'm specifically looking for an encryption algorithm like Blowfish that will encrypt data in the same footprint as the original data. ...
    (comp.sys.hp.mpe)
  • Re: Ruby on HP-UX
    ... I'll work on at least openssl, since it is the squeaky wheel at the moment. ... you refering to libcrypto, when the error is related to crypto? ... Make sure that these are all available as either shared libraries ... Otherwise the HP-UX dynamic linker will choke at runtime because ...
    (comp.lang.ruby)