Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2009-237

Mandriva Linux Security Advisory 2009-237 – ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello. The NSS library library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spooof certificates by using MD2 design flaws the scope of this issue is currently limited because the amount of computation required is still large. This update provides a solution to these vulnerabilities.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81493/MDVSA-2009-237.txt

Source: https://packetstormsecurity.com/files/81493/Mandriva-Linux-Security-Advisory-2009-237.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061