Forum Moderators: phranque

Message Too Old, No Replies

OpenSSL Vulnerability Discovered

         

engine

6:47 pm on Mar 5, 2010 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



OpenSSL Vulnerability Discovered [theregister.co.uk]
Computer scientists say they've discovered a "severe vulnerability" in the world's most widely used software encryption package that allows them to retrieve a machine's secret cryptographic key.

The bug in the OpenSSL cryptographic library is significant because the open-source package is used to protect sensitive data in countless applications and operating systems throughout the world. Although the attack technique is difficult to carry out, it could eventually be applied to a wide variety of devices, particularly media players and smartphones with anti-copying mechanisms.


An OpenSSL official, who asked that his name not be published, said engineers are in the process of pushing out a patch and stressed the attack is difficult to carry out in real-world settings.

bill

6:43 am on Mar 6, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



...stressed the attack is difficult to carry out in real-world settings.

That's usually the case with these. This isn't one to be overly concerned with. I'd keep an eye out for the update of this software if I was using it.