Threat Level: green Handler on Duty: Yee Ching Tok

SANS ISC: OpenSSL Security Update SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
OpenSSL Security Update

OpenSSL has issued a security update for the CMS and S/MIME Bleichenbacher attack (CVE-2012-0884). "SSL/TLS applications are *NOT* affected by this problem since the SSL/TLS code does not use the PKCS#7 or CMS decryption code." [1]

OpenSSL 0.9.8u and OpenSSL 1.0.0h are available for download here.

[1] http://www.openssl.org/news/secadv_20120312.txt
[2] http://www.openssl.org/source/

-----------

Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu

Guy

501 Posts
ISC Handler
Mar 12th 2012

Sign Up for Free or Log In to start participating in the conversation!