Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2008-107

Mandriva Linux Security Advisory – Testing using the Codenomicon TLS test suite discovered a flaw in the handling of server name extension data in OpenSSL 0.9.8f and OpenSSL 0.9.8g. If OpenSSL has been compiled using the non-default TLS server name extensions, a remote attacker could send a carefully crafted packet to a server application using OpenSSL and cause a crash. Testing using the Codenomicon TLS test suite discovered a flaw if the ‘Server Key exchange message’ is omitted from a TLS handshake in OpenSSL 0.9.8f and OpenSSL 0.9.8g. If a client connects to a malicious server with particular cipher suites, the server could cause the client to crash.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66781/MDVSA-2008-107.txt

Source: https://packetstormsecurity.com/files/66781/Mandriva-Linux-Security-Advisory-2008-107.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061