iTnews
  • Home
  • News
  • Technology
  • Security

OpenSSL patches nine security flaws

By Juha Saarinen on Aug 7, 2014 5:35PM
OpenSSL patches nine security flaws

Code security audits kicking in.

The OpenSSL open source cryptographic library - whose software underpins many thousands of internet sites - today issued patches for nine security flaws in its three main code branches.

None of the vulnerabilities can be exploited to leak information as is possible with the "Heartbleed" flaw.

Several can be used for denial of service (DoS) attacks against the Datagram Transport Layer Security (DTLS) protocol, the OpenSSL team said.

One of the flaws in the OpenSSL server discovered by Googlers David Benjamin and Adam Langley, the first to discover the Heartbleed vulnerability, can be exploited to allow attackers to force a negotiation with a client to pick the older and  less secure Transport Layer Security (TLS) 1.0 protocol, instead of more modern, more secure ones.

AusCERT information security analyst Marco Ostini told iTnews that the current spate of vulnerabilities isn't as serious as the last couple of OpenSSL advisories.

Ostini noted that there is now plenty more industry input and code audit for the OpenSSL project.

"It's lovely to see OpenSSL bugs being identified by Google, LogMeIn and Codenomicon, andsee  them being attended to by OpenSSL developers," Ostini said.

The OpenSSL project recommends that users upgrade their existing software as soon as feasible, as per below.

  • OpenSSL 0.9.8 users should upgrade to 0.9.8zb
  • OpenSSL 1.0.0 users should upgrade to 1.0.0n.
  • OpenSSL 1.0.1 users should upgrade to 1.0.1i.

Vulnerabilities patched in the latest advisory include CVE-2014-3508, CVE-2014-5139, CVE-2014-3509, CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3510, CVE-2014-3511 and CVE-2014-3512.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
bleedcryptographyheartopensslsecurityvulnerability

Partner Content

How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Why rethinking your CMS is crucial for customer retention
Promoted Content Why rethinking your CMS is crucial for customer retention
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Juha Saarinen
Aug 7 2014
5:35PM
0 Comments

Related Articles

  • OpenSSL subject to remote memory corruption
  • Java 15 introduced a cryptographic vulnerability
  • Mitsubishi manufacturing controller software inherited OpenSSL bugs
  • Cisco data centre management software needs vulnerabilities patched
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

Australian court finds insurer not liable for ransomware clean-up costs

Australian court finds insurer not liable for ransomware clean-up costs

NBN Co proposes to axe CVC across all plans by mid-2026

NBN Co proposes to axe CVC across all plans by mid-2026

ADHA extends Accenture's My Health Record support deal for $100m

ADHA extends Accenture's My Health Record support deal for $100m

Digital Nation

Australia will lose 11 percent of jobs to automation by 2040: Forrester
Australia will lose 11 percent of jobs to automation by 2040: Forrester
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
Domino’s invests in observability for zero contact delivery
Domino’s invests in observability for zero contact delivery
Metaverses on the agenda for Dominello, Husic ministerial meeting
Metaverses on the agenda for Dominello, Husic ministerial meeting
Criteo to fork out $94.7m for consent breaches
Criteo to fork out $94.7m for consent breaches
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.