[ale] OpenSSL Broken, Upgrade Now

David Tomaschik david at systemoverlord.com
Mon Apr 7 19:14:08 EDT 2014


TL;DR: Upgrade OpenSSL to >= 1.0.1g immediately, consider replacing keys.
 Not as bad as Debian OpenSSL bug, but worse than "goto fail;".

"The Heartbleed Bug is a serious vulnerability in the popular OpenSSL
cryptographic software library. This weakness allows stealing the
information protected, under normal conditions, by the SSL/TLS encryption
used to secure the Internet. SSL/TLS provides communication security and
privacy over the Internet for applications such as web, email, instant
messaging (IM) and some virtual private networks (VPNs).

The Heartbleed bug allows anyone on the Internet to read the memory of the
systems protected by the vulnerable versions of the OpenSSL software. This
compromises the secret keys used to identify the service providers and to
encrypt the traffic, the names and passwords of the users and the actual
content. This allows attackers to eavesdrop communications, steal data
directly from the services and users and to impersonate services and users."

http://heartbleed.com

-- 
David Tomaschik
OpenPGP: 0x5DEA789B
http://systemoverlord.com
david at systemoverlord.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.ale.org/pipermail/ale/attachments/20140407/4e4d472e/attachment.html>


More information about the Ale mailing list