Posts Tagged ‘Security’

OpenSSH security advisory: legacy certificate signing in 5.6/5.7

This item was filled under [ Tools ]

OpenSSH Security Advisory: legacy-certs.adv This document may be found at: http://www.openssh.com/txt/legacy-cert.adv 1. Vulnerability Legacy certificates generated by OpenSSH might contain data from the stack thus leaking confidential information. 2. Affected configurations OpenSSH 5.6 and OpenSSH 5.7 only when generating legacy certificates. These must be specifically requested using the “-t” option on the ssh-keygen CA command-line. [...]

Continue reading...

Tagged with: [ , , ]

OpenSSL security advisory

This item was filled under [ OpenSSL ]

OpenSSL Ciphersuite Downgrade Attack A flaw has been found in the OpenSSL SSL/TLS server code where an old bug workaround allows malicous clients to modify the stored session cache ciphersuite. In some cases the ciphersuite can be downgraded to a weaker one on subsequent connections. The OpenSSL security team would like to thank Martin Rex [...]

Continue reading...

Tagged with: [ , , ]

OpenSSL Security Advisory

This item was filled under [ OpenSSL ]

TLS extension parsing race condition. A flaw has been found in the OpenSSL TLS server extension code parsing which on affected servers can be exploited in a buffer overrun attack. The OpenSSL security team would like to thank Rob Hulswit for reporting this issue. The fix was developed by Dr Stephen Henson of the OpenSSL [...]

Continue reading...

Tagged with: [ , , ]