cURL / Mailing Lists / curl-library / Single Mail

curl-library

OpenSSL bugs

From: Jeff Pohlmeyer <yetanothergeek_at_yahoo.com>
Date: Wed, 1 Oct 2003 17:19:15 -0700 (PDT)

Quote from SuSE Security Update 2003-10-01:

"While checking the openssl implementation with a tool-kit from NISCC
several errors were revealed most are ASN.1 encoding issues that
causes a remote denial-of-service attack on the server side and
possibly lead to remote command execution.

There are two problems with ASN.1 encoding that can be triggered either
by special ASN.1 encodings or by special ASN.1 tags.

In debugging mode public key decoding errors can be ignored but
also lead to a crash of the verify code if an invalid public key
was received from the client.

A mistake in the SSL/TLS protocol handling will make the server accept
client certificates even if they are not requested. This bug makes
it possible to exploit the bugs mentioned above even if client
authentication is disabled.

There is no other solution known to this problem than updating to the
current version."

 - This looks like mostly server-side problems, so I don't think it
would affect libcurl, but it might be a good idea to upgrade just
in case...

See also:
  http://www.openssl.org/

__________________________________
Do you Yahoo!?
The New Yahoo! Shopping - with improved product search
http://shopping.yahoo.com

-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
Received on 2003-10-02