Get a Pentest and security assessment of your IT network.

Advisories

SUSE Security Announcement SUSE-SA:2009:057

SUSE Security Announcement – The TLS/SSLv3 protocol as implemented in openssl prior to this update was not able to associate already sent data to a renegotiated connection. This allowed man-in-the-middle attackers to inject HTTP requests in a HTTPS session without being noticed. For example Apache’s mod_ssl was vulnerable to this kind of attack because it uses openssl. It is believed that this vulnerability is actively exploited in the wild to get access to HTTPS protected web-sites. Please note that renegotiation will be disabled for any application using openssl by this update and may cause problems in some cases. Additionally this attack is not limited to HTTP.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82770/SUSE-SA-2009-057.txt

Source: https://packetstormsecurity.com/files/82770/SUSE-Security-Announcement-SUSE-SA-2009-057.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1