Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

DoS bugs in OpenSSL

From: Todd C. Miller <Todd.Miller(at)courtesan.com>
Date: Fri Oct 03 2003 - 18:45:24 EDT


The use of certain ASN.1 encodings or malformed public keys may allow an attacker to mount a denial of service attack against applications linked with ssl(3). This does not affect OpenSSH.

For full details, please see the OpenSSL advisory:

    http://www.openssl.org/news/secadv_20030930.txt

A fix has been committed to the OpenBSD 3.2 and 3.3 -stable branches. Patches are also available for OpenBSD 3.2 and 3.3.

Patch for OpenBSD 3.2:

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/020_asn1.patch

Patch for OpenBSD 3.3:

    ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.3/common/007_asn1.patch Received on Fri Oct 3 19:08:34 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:46:07 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library