ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

OpenSSL shuts attack holes

Published: 18 Mar 2004 08:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The group behind OpenSSL, a widely used open-source Web security program, released two patches for security flaws to block potential denial-of-service attacks, the organisation's developers said on Wednesday.

The flaws affect more than Linux systems that have the software installed. They could also hobble many routers and network devices that incorporate the software. Cisco Systems released an advisory on Wednesday, saying its PIX firewall devices and some routers could be affected.

OpenSSL is an open implementation of Secure Sockets Layer (SSL) encryption, which is used by almost all Web browsers as a way to secure data that travels over the public Internet. The software also forms the basis of a popular component of the Apache Web server, which accounts for more than two-thirds of the servers on the Internet.

The flaws don't give an attacker the opportunity to take control of a computer or a device, but they do create the possibility for specially crafted data to crash the software. Such a denial-of-service attack could stop users from logging in to a server and prevent administrators from managing network devices. In some cases, the flaws will crash the device, causing wider network outages, according to several advisories.

A survey conducted last November found that nearly half of the Web servers involved in the study ran a version of OpenSSL that hadn't been recently patched. A flaw in the Web server component based of OpenSSL was responsible for allowing the Linux Slapper worm to spread in September 2002.

Red Hat and Novell's SuSE Linux subsidiary both ship Linux systems that incorporate OpenSSL.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
59 out of 105 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Network Systems Engineer

Hands-on knowledge of configuration and maintenance of Cisco devices; routers in the 7200 family, Switches in the 6500+ range and Pix Firewalls - ...

UNIX Redhat & Windows Senior Administrator 35k Warrington

Skills required include: - Desirable skills include experience of Red Hat Linux, Windows Server 2003 and exposure to ISO and ITIL - Knowledge of ...

Systems Administrator- SPECIALIST SOFTWARE HOUSE- London WC (40k)

Operating systems run on a Microsoft platform including Windows 2000/03 Server, Exchange 2000/03, IP Networking, CISCO (routers & switches) and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment