High-severity flaw found in OpenSSL

By

Users with version 1.1.0 advised to upgrade.

The popular open source cryptographic library project OpenSSL has patched a vulnerability that could cause the software to crash on both the client and server side, a flaw rated as high severity.

High-severity flaw found in OpenSSL

Discovered by Red Hat engineer Joe Orton last month, the vulnerability is marked as CVE-2017-3733 and could be used in denial of service attacks.

OpenSSL version 1.1.0 is affected, the project's security advisory said.

"During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL to crash (dependent on ciphersuite)," the advisory said.

Users of the affected version are advised to upgrade to version 1.1.0e. Version 1.0.2 is not affected by the flaw.

The OpenSSL project also reminded users that as of December 31 last year, version 1.0.1 is no longer supported and won't receive security updates.

Versions 0.9.8 and 1.0.0 stopped receiving security updates on December 31 2015, the project said.

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Victoria's Secret pulls down website amid security incident

Victoria's Secret pulls down website amid security incident

Log In

  |  Forgot your password?