Heartbleed - critical vulnerability in OpenSSL 1.0.1 through 1.0.1f (inclusive)

Gene <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAMx+XZ3M0gc8nWSYAPBENC3EqR_A+ngQC-yoKMVh0edGVoq_Mw@mail.gmail.com>
Server admins take note:

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL
cryptographic software library. This weakness allows stealing the
information protected, under normal conditions, by the SSL/TLS
encryption used to secure the Internet.

Bug is in the OpenSSL's implementation of the TLS/DTLS (transport
layer security protocols) heartbeat extension (RFC6520). When it is
exploited it leads to the leak of memory contents from the server to
the client *and* from the client to the server.

The Heartbleed bug allows anyone on the Internet to read the memory of
the systems protected by the vulnerable versions of the OpenSSL
software. This compromises the secret keys used to identify the
service providers and to encrypt the traffic, the names and passwords
of the users and the actual content. This allows attackers to
eavesdrop communications, steal data directly from the services and
users and to impersonate services and users.

More info at http://heartbleed.com/

Summary:
*Patch OpenSSL to 1.0.1g *immediately*
*Generate new keypairs
*Revoke the old keypairs that were just superseded
*Change all passwords used on the affected systems
*Invalidate all session keys and cookies
*Evaluate the actual content handled by the vulnerable servers that
could have been leaked, and reacting accordingly.
*Evaluate any other information that could have been revealed, like
memory addresses and security measures

Known affected systems:
*Debian Wheezy (stable), OpenSSL 1.0.1e-2+deb7u4
*Ubuntu 12.04.4 LTS, OpenSSL 1.0.1-4ubuntu5.11
*CentOS 6.5, OpenSSL 1.0.1e-15
*Fedora 18, OpenSSL 1.0.1e-4
*OpenBSD 5.3 (OpenSSL 1.0.1c 10 May 2012) and 5.4 (OpenSSL 1.0.1c 10 May 2012)
*FreeBSD 8.4 (OpenSSL 1.0.1e) and 9.1 (OpenSSL 1.0.1c)
*NetBSD 5.0.2 (OpenSSL 1.0.1e)
*OpenSUSE 12.2 (OpenSSL 1.0.1c)

Normal users:
*Be very prompt in installing software updates for the next month or so :)

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.