You are here: silicon.com > Hardware > Servers

Servers

Three open source flaws plugged

UK government alerted users to the problem...

By Robert Lemos

Published: 2 October 2003 08:27 GMT

An open-source group that maintains software for securing communications released a patch on Tuesday to fix several vulnerabilities that were found during a security test by the UK government.

The security flaws exist in the OpenSSL Project's version of the secure sockets layer (SSL) software used by websites and browsers to cryptographically secure data. Two of the flaws could lead to a denial-of-service attack, and a third may allow an attacker to break into a system from the Internet.

The flaws were found when the UK government put the software through rigorous testing, said Mark Cox, a developer on the OpenSSL security team.

"We certainly know of no exploits yet," he said. "These were found by the good guys."

Not to be confused with the OpenSSH project - SSH stands for secure shell - which has patched its software twice in the last month, the OpenSSL Project develops and maintains an open-source version of SSL software. A year ago, the Slapper worm infected Linux computers that hadn't been patched to fix a different hole in the same software.

Cox said that a specially crafted digital certificate could crash the OpenSSL software through either of two flaws, causing a denial-of-service attack. The third flaw could result in a security hole that could allow online vandals to attack a server or enable a worm to spread. All versions of OpenSSL, up to and including 0.9.6j and 0.9.7b, are affected, according to an advisory issued by the group.

So far, most Linux distributors, including Red Hat and SuSE, have released patches for the flaws. Cisco Systems also has released patches. The networking gear maker uses the software in a number of its products.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Seb Janacek Minority Report: Mac Mini - a real nowhere machine What could it have become with a little more love and attention?

Bethan Jones Can I use a netbook as my everyday work machine? Part II silicon.com sub editor reveals whether her netbook delivered


  • Jobs
FIX Protocol Support - Perl - Electronic Trading - Permanent - London

FIX Support Analyst with strong client facing skills required for a leading boutique financial software organisation. An in-depth knowledge of FIX is ...

Technical Analyst - SMS, SCCM, WSUS - Patch & Release

The role will involve the assessment of vulnerabilities, patch testing and application deployment via remote systems such as SMS/SCCM, WSUS and ...

Equities, FIX, Support, Equity Derivatives, Banking

Equities, FIX, Support, Equity Derivatives, BankingOur client a tier one Investment Bank are seeking a bright individual with Equities, Trading ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: