High-severity flaw found in OpenSSL

By

Users with version 1.1.0 advised to upgrade.

The popular open source cryptographic library project OpenSSL has patched a vulnerability that could cause the software to crash on both the client and server side, a flaw rated as high severity.

High-severity flaw found in OpenSSL

Discovered by Red Hat engineer Joe Orton last month, the vulnerability is marked as CVE-2017-3733 and could be used in denial of service attacks.

OpenSSL version 1.1.0 is affected, the project's security advisory said.

"During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL to crash (dependent on ciphersuite)," the advisory said.

Users of the affected version are advised to upgrade to version 1.1.0e. Version 1.0.2 is not affected by the flaw.

The OpenSSL project also reminded users that as of December 31 last year, version 1.0.1 is no longer supported and won't receive security updates.

Versions 0.9.8 and 1.0.0 stopped receiving security updates on December 31 2015, the project said.

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?