TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OpenSSL high-severity bug – affects 1.1.1d, 1.1.1e, 1.1.1f

189 点作者 AngeloR大约 5 年前

11 条评论

9wzYQbTYsAIc大约 5 年前
&gt; This issue was found by Bernd Edlinger and reported to OpenSSL on 7th April 2020. It was found using the new static analysis pass being implemented in GCC, -fanalyzer.<p>2 week turnaround time, not bad I guess, for something found by a static analyzer.
judge2020大约 5 年前
At least it&#x27;s just DOS and not anything like heartbleed.
nayuki大约 5 年前
What popular software contain these vulnerable versions of the OpenSSL library?
评论 #22937313 未加载
评论 #22937401 未加载
评论 #22939501 未加载
评论 #22942649 未加载
pronoiac大约 5 年前
Checking out packages.ubuntu.com, it looks like the only version impacted is &quot;focal;&quot; the other versions are too old.
评论 #22939033 未加载
agumonkey大约 5 年前
Now I know why arch pushed a new version this afternoon.
codewiz大约 5 年前
Is BoringSSL affected?
评论 #22941324 未加载
usr1106大约 5 年前
So how widely TLS 1.3 is<p>a) used<p>b) enabled in either client or server?
nayuki大约 5 年前
OpenSSL vulnerabilities: The gift that keeps on giving.
评论 #22939637 未加载
stuff4ben大约 5 年前
This would primarily affect web servers exposing SSH access to the public right? I suppose it also affects internally accessible servers as well but to a lesser degree in terms of priority.
评论 #22937689 未加载
vladsanchez大约 5 年前
OpenSSL is the culprit of a MacPort installation issue (vde2) for which there is no maintainer. It exposes operational vulnerability to unmaintained open source software.
评论 #22938992 未加载
评论 #22938652 未加载
评论 #22938287 未加载
snvzz大约 5 年前
Sure, let&#x27;s continue to reward incompetence by further funding openssl.<p>In a sane world, everybody would have switched to libressl ages ago.
评论 #22940708 未加载
评论 #22957134 未加载
评论 #22938265 未加载