Neue OpenSSL Lücke - Fix für Donnerstag erwartet

Rund um die Sicherheit des Systems und die Applikationen
Post Reply
User avatar
daemotron
Administrator
Administrator
Posts: 2641
Joined: 2004-01-21 17:44
Contact:
 

Neue OpenSSL Lücke - Fix für Donnerstag erwartet

Post by daemotron »

Siehe https://mta.openssl.org/pipermail/opens ... 00037.html

Was genau kaputt ist, verraten die OpenSSL-Entwickler derzeit noch nicht. Allerdings stufen sie die Lücke als "high severity" ein. Das beudetet:
OpenSSL Security Policy wrote:high severity issues. This includes issues affecting common configurations which are also likely to be exploitable. Examples include a server DoS, a significant leak of server memory, and remote code execution. These issues will be kept private and will trigger a new release of all supported versions. We will attempt to keep the time these issues are private to a minimum; our aim would be no longer than a month where this is something under our control, and significantly quicker if there is a significant risk or we are aware the issue is being exploited.
Also wärmt Eure Paketmanager, Tinderboxen, Pulvertürme etc. schon mal vor - diese Lücke will man sicherlich schnell vom System bekommen...
“Some humans would do anything to see if it was possible to do it. If you put a large switch in some cave somewhere, with a sign on it saying 'End-of-the-World Switch. PLEASE DO NOT TOUCH', the paint wouldn't even have time to dry.” — Terry Pratchett, Thief of Time
Post Reply