Vulnerability in SSL/TLS protocol | Linux Today

Vulnerability in SSL/TLS protocol

Written By
Web Webster
Web Webster
Nov 6, 2009

“The precise effects of the problem are not discussed in the
reports. It would, however, appear to be possible to manipulate
HTML content from websites during data transfer and, for example,
inject malicious code.

“The crux of the problem is, rather than a flawed
implementation, a design flaw in the TLS protocol when
renegotiating parameters for an existing TLS connection. This
occurs when, for example, a client wants to access a secure area on
a web server which requires the requesting client certificates.
When the server establishes that is the case, it begins a
renegotiation to obtain the appropriate client certificate. The
original request gets replayed during this renegotiation as if it
had been authenticated by the client certificate, but it has not.
The discoverer of the problem describes this as an “authentication
gap”.”


Complete Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.