Domeka
06.02.2012., 09:16:52 *
Welcome, Guest. Please login or register.

Login with username, password and session length
 
   Home   Help Search GoogleTagged Contact Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Sigurnosni nedostatak unutar programskog paketa OpenSSL  (Read 410 times)
0 Members and 1 Guest are viewing this topic.
The MasteR
Administrator
Full Member
*****

Karma: +20/-0
Offline Offline

Gender: Male
Posts: 168



View Profile WWW
« on: 23.09.2009., 07:25:35 »

U besplatnoj implementaciji SSL (eng. Secure Sockets Layer) protokola, paketu OpenSSL, otkriveno je više ranjivosti. Riječ je o različitim DoS (eng. Denial of Service) ranjivostima u implementaciji DTLS (eng. Datagram Transport Layer Security) protokola te o slabostima MD2 algoritma za izračunavanje sažetaka poruke (eng. hash).

Zbog ranjivosti spomenutog algoritma onemogućeno je njegovo korištenje u novijim inačicama alata. Osim toga, otklonjeni su svi uočeni DoS problemi.

Ove ranjivost ima oznake CVE-2009-2409 i DSA-1888-1.

Ranjivost je ispravljena u paketu openssl verzije 0.9.8c-4etch9 za Debian etch te verzije 0.9.8g-15+lenny5 za Debian lenny.

Nove pakete za Debian možete instalirati na uobičajeni način:

Code:
apt-get update
apt-get upgrade

Ako želite instalirati samo ove pakete:

Code:
apt-get update
apt-get -y install openssl libssl0.9.8

Više informacija na:

Debian Security DSA-1888
Logged

Bavim se mreznom implementacijom - sistemac - Linux, CCNA, CCNP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.8 | SMF © 2006-2008, Simple Machines LLC | Sitemap Valid XHTML 1.0! Valid CSS!
Page created in 0.08 seconds with 22 queries.

Google visited last this page 27.01.2012., 12:45:35