Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Secure servers compromised by SSL bug

OpenSSL produces fix.

Article comments

The OpenSSL project has warned of a security bug that could allow attacks on secured servers.

OpenSSL is an open-source, multi-platform implementation of the SSL and TLS cryptographic protocols, which are used by commercial websites for secure credit-card transactions, among other uses.

The flaw means that an attacker could trick a server into using older, insecure versions of SSL, the project said. Some sites allow older versions of SSL to be used, but only under particular conditions, such as if a client can't support the more secure SSL 3.0 and TLS 1.0.

"An attacker acting as a 'man in the middle' can force a client and a server to negotiate the SSL 2.0 protocol even if these parties both support SSL 3.0 or TLS 1.0," the project said in an advisory on Tuesday. "The SSL 2.0 protocol is known to have severe cryptographic weaknesses and is supported as a fallback only."

Researcher Yutaka Oiwa of the Research Centre for Information Security at Japan's National Institute of Advanced Industrial Science and Technology (AIST) first alerted OpenSSL of the problem. The bug is in an option called SSL_OP_MSIE_SSLV2_RSA_PADDING, intended to help work around interoperability problems. However, the option also disables a verification step needed to prevent active protocol-version rollback attacks, the advisory said.

The bug affects all versions of OpenSSL up to 0.9.7h and 0.9.8a, and is likely to affect any applications using OpenSSL's SSL/TLS implementation, the group said. Versions 0.9.8a and 0.9.7h have been released to fix the problem, with upgrades available via a number of mirror sites.

Users can also apply a patch, available here, or disable SSL 2.0 entirely.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *