Heartbleed - critical vulnerability in OpenSSL 1.0.1 through 1.0.1f (inclusive)
Gene <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.dunedin.general |
|---|---|
| Message-ID | <CAMx+XZ3M0gc8nWSYAPBENC3EqR_A+ngQC-yoKMVh0edGVoq_Mw@mail.gmail.com> |
Server admins take note: The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. Bug is in the OpenSSL's implementation of the TLS/DTLS (transport layer security protocols) heartbeat extension (RFC6520). When it is exploited it leads to the leak of memory contents from the server to the client *and* from the client to the server. The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop communications, steal data directly from the services and users and to impersonate services and users. More info at http://heartbleed.com/ Summary: *Patch OpenSSL to 1.0.1g *immediately* *Generate new keypairs *Revoke the old keypairs that were just superseded *Change all passwords used on the affected systems *Invalidate all session keys and cookies *Evaluate the actual content handled by the vulnerable servers that could have been leaked, and reacting accordingly. *Evaluate any other information that could have been revealed, like memory addresses and security measures Known affected systems: *Debian Wheezy (stable), OpenSSL 1.0.1e-2+deb7u4 *Ubuntu 12.04.4 LTS, OpenSSL 1.0.1-4ubuntu5.11 *CentOS 6.5, OpenSSL 1.0.1e-15 *Fedora 18, OpenSSL 1.0.1e-4 *OpenBSD 5.3 (OpenSSL 1.0.1c 10 May 2012) and 5.4 (OpenSSL 1.0.1c 10 May 2012) *FreeBSD 8.4 (OpenSSL 1.0.1e) and 9.1 (OpenSSL 1.0.1c) *NetBSD 5.0.2 (OpenSSL 1.0.1e) *OpenSUSE 12.2 (OpenSSL 1.0.1c) Normal users: *Be very prompt in installing software updates for the next month or so :) _______________________________________________ DunLUG mailing list [email protected] http://lists.ethernal.org/listinfo/dunlug DunLUG Wiki - http://dunlug.kallisti.net.nz/