Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 







Current Newswire:

Ubuntu, the Manual Project

Transcoding 50 fps Interlaced AVCHD to 50 fps Progressive x264 with MEncoder

Debian GNU/Linux Milestones

Do you know which more things vlc mediplayer can do ?

Install The Newest Firefox PPA with command "add-apt-repository" (Karmic)

Hidden Linux : Learning to love KDE 4 (part I)

Change default applications easily in GNOME

Blu-Ray Comes to Linux, Finally!

Kodak Easyshare Wireless Picture Frame - How to show everyone whats on your frame

The Great Open Source Netbook Interface Race




Technical Specialist II – PC – LAN (AZ)
Next Step Systems
US-AZ-Scottsdale

Justtechjobs.com Post A Job | Post A Resume
:Widespread vulnerabilities found in programs which use OpenSSL
Widespread vulnerabilities found in programs which use OpenSSL
Jan 9, 2009, 17 :03 UTC (10 Talkback[s]) (4780 reads)

"The most important affected program is ISC Bind, which is the most widely used DNS server on the internet. A flaw in its validation of signatures on DNSSEC replies means that the server may be vulnerable to DNS spoofing attacks even where DNSSEC is in use. Bind have released BIND 9.6.0-P1 this morning to fix this bug.

"The common mistake is in the checking of return values from functions in OpenSSL that check digital signatures. Programmers have failed to allow for all the possible return values of the EVP_VerifyFinal function, and as a result some cases where the signature has not been successfully checked can be mistakenly treated as successfully verified."

Complete Story

Related Stories:
Perspectives Extension Improves HTTPS Security(Oct 21, 2008)
Flaws Found in BSD, Linux Software Updaters(Jul 15, 2008)
After Debian's Epic SSL Blunder, A World of Hurt for Security Pros(May 22, 2008)
Flaws Reported in Validated OpenSSL Module v1.1.1(Nov 29, 2007)
All Systems Go for Validation of Updated OpenSSL Module(Sep 12, 2007)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
Gee the linux boys copied UNIX line for  ...   Line for line copy of UNIX   
darryl
Jan 9, 2009, 19:34:34
 
Your comment is so inane, I don't kn ...   Re: Line for line copy of UNIX   
txtechdog
Jan 9, 2009, 20:09:56
 
As anyone who has installed openssl woul ...   http://www.openssl.org/   
Arthur Marsh
Jan 9, 2009, 20:25:11
 
> Your comment is so inane, I don't  ...   Re: Re: Line for line copy of UNIX   
Tony OBryan
Jan 9, 2009, 20:58:13
 
> > Your comment is so inane, I don' ...   Re: Re: Re: Line for line copy of UNIX   
Jeff Cobb
Jan 9, 2009, 21:05:06
 
I get the impression that he *does* beli ...   Re: Re: Re: Re: Line for line copy of UNIX   
Bernard Swiss
Jan 10, 2009, 03:11:04
 
> Gee the linux boys copied UNIX line fo ...   Re: Line for line copy of UNIX in Windows   
Ken Jennings
Jan 10, 2009, 06:18:33
 
Apparently forgetting that the CEO of SC ...   Darryl or Darl   
blackhole
Jan 10, 2009, 10:01:59
 
> Apparently forgetting that the CEO of  ...   Re: Darryl or Darl   
Jeff Cobb
Jan 11, 2009, 03:00:44
 
> Gee the linux boys copied UNIX line fo ...   Re: Line for line copy of UNIX   
Rainer Weikusat
Jan 11, 2009, 12:56:25
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers