TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OpenSSL Security Advisory

129 pointsby eyearequealmost 10 years ago

6 comments

ctzalmost 10 years ago
Here&#x27;s a writeup of CVE-2015-1788:<p><a href="https:&#x2F;&#x2F;jbp.io&#x2F;2015&#x2F;06&#x2F;11&#x2F;cve-2015-1788-openssl-binpoly-hang&#x2F;" rel="nofollow">https:&#x2F;&#x2F;jbp.io&#x2F;2015&#x2F;06&#x2F;11&#x2F;cve-2015-1788-openssl-binpoly-hang...</a><p>It&#x27;s embarrassing rather than terribly dangerous.<p>edit: Please note: there are other issues in this advisory. You should read the advisory, first and foremost.
评论 #9700832 未加载
评论 #9700324 未加载
ikeboyalmost 10 years ago
In the meantime, latest stable releases of Chrome and Firefox are <i>still</i> vulnerable to Logjam. Is it that hard to fix?
评论 #9702061 未加载
评论 #9701711 未加载
epmatswalmost 10 years ago
I wonder how many of these are found by hand versus with automated tools like Asan and AFL. Seems like some of these would be really hard to spot...
评论 #9700494 未加载
评论 #9700379 未加载
colinbartlettalmost 10 years ago
Layman&#x27;s explanation? I should apt-get update &amp;&amp; apt-get upgrade?
评论 #9703186 未加载
therealmarvalmost 10 years ago
Good luck in updating it in OS X (try running `ssh -V` there). Good that OS X will update to a more recent version in El Capitan and also switch to LibreSSL (great step forward).
评论 #9700329 未加载
评论 #9700336 未加载
Animatsalmost 10 years ago
<i>&quot;X509_cmp_time does not properly check the length of the ASN1_TIME string and can read a few bytes out of bounds.&quot;</i><p>OpenSSL in C has had range errors discovered for over a decade now. Short of going to a safe language or full machine proofs of correctness, it&#x27;s never going to be fixed. &quot;Many eyes&quot; don&#x27;t help.<p>(Of course, one wonders how many OpenSSL security holes are deliberate backdoors.)
评论 #9702865 未加载