New York Web Design News October 2 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

OpenSSL Patches 3 Holes
Web Design & Technology News, October 2, 2003

MSFT & Google Allies?
Adobe Suite Boosts Sales
Google Buys Sprink Ads
IPO for Google?
Tech Spending Outlook
Confused by Search Engines?
Google's Personalization
VeriSign Rebutts Critics
AOL Extends Google Ties

VeriSign Fires Back
MSFT Drops LookSmart
MSFT Fixes Bad Patch
VeriSign Halts SiteFinder
Comcast Doubles Speed
OpenSSL Patches 3 Holes
Google Acquires Kaltix
Lycos Uses Google AdSense

More Web Design News:
2008 Current News
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



October 2, 2003

An open-source group that maintains software for securing communications released a patch on Tuesday to fix several vulnerabilities that were found during a security test by the U.K. government.
By Robert Lemos

The security flaws exist in the OpenSSL Project's version of the secure sockets layer (SSL) software used by Web sites and browsers to cryptographically secure data. Two of the flaws could lead to a denial-of-service attack, and a third may allow an attacker to break into a system from the Internet.

The flaws were found when the U.K. government put the software through rigorous testing, said Mark Cox, a developer on the OpenSSL security team.

"We certainly know of no exploits yet," he said. "These were found by the good guys."

Not to be confused with the OpenSSH project -- SSH stands for secure shell -- which has patched its software twice in the last month, the OpenSSL Project develops and maintains an open-source version of SSL software. A year ago, the Slapper worm infected Linux computers that hadn't been patched to fix a different hole in the same software.

Cox said that a specially crafted digital certificate could crash the OpenSSL software through either of two flaws, causing a denial-of-service attack. The third flaw could result in a security hole that could allow online vandals to attack a server or enable a worm to spread. All versions of OpenSSL, up to and including 0.9.6j and 0.9.7b, are affected, according to an advisory issued by the group.

So far, most Linux distributors, including Red Hat and SuSE, have released patches for the flaws. Cisco Systems also has released patches. The networking gear maker uses the software in a number of its products.

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com