Unholy trinity of Open SSL vulns
Security alert
Posted in Security, 19th March 2004 13:54 GMT
Free whitepaper – Transforming IT culture
Updated versions of Open SSL have been released following this week's announcement of three potentially troublesome security vulnerabilities.
These could be exploited by attackers to launch denial of service attacks against routers or servers running the ubiquitous security protocol, security clearing house CERT warns.
OpenSSL is derived from an open source project of the same name focused at offering Secure Sockets Layer and Transport Layer Security technology, as well as a general purpose cryptography library. The technology is widely used across *nix environments and networking equipment.
The first flaw stems for a bug in a SSL handshake function used by OpenSSL versions 0.9.6.c to 0.9.6k and versions 0.9.7a to 0.9.7c. The second vulnerability involves Kerberos cipher suites and affects 0.9.7a, 0.9.7b and 0.9.7c. Lastly, OpenSSL prior to version 0.9.6d fails to correctly handle unknown SSL/TLS message types, again triggering a DoS risk.
Users of potentially vulnerable systems are advised to upgrade to version 0.9.6m or 0.9.7d of OpenSSL. Most *nix vendors systems and Linux distributions are also publishing their corresponding patches.
An advisory from the OpenSSL project is here. ®
Related stories
Brits pound OpenSSL bugs
Admins slow to tackle SSL security risks

Register Research on: Application Platforms
Secure Mobile Working
The Impact of IT Security Attitudes
The Evolving Security Landscape
The Register's Green Computing Debate
