Peaches Posted December 9, 2010 Report Share Posted December 9, 2010 New version of OpenSSL fixes two vulnerabilities Version 1.0.0c of the free OpenSSL SSL implementation fixes two vulnerabilities. A flaw in an older workaround for Netscape browsers and servers can be remotely exploited to make an OpenSSL server downgrade the ciphersuite to a weaker one for subsequent connections. This can potentially simplify the cracking of encrypted connections. The update simply disables the workaround. Another flaw in the implementation of the "Password Authenticated Key Exchange by Juggling" protocol (J-PAKE ) allows intruders to authenticate themselves without a secret key. While this flaw has been fixed in the current version, the developers point out that their implementation is still experimental and not compiled by default. http://www.h-online.com/security/news/item/New-version-of-OpenSSL-fixes-two-vulnerabilities-1150044.html Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.