LWN.net Logo

OpenSSL: plaintext exposure vulnerability

Package(s):openssl CVE #(s):CAN-2003-0078
Created:February 19, 2003 Updated:March 6, 2003
Description: A vulnerability has been found in OpenSSL that, given the right conditions, could lead to the exposure of transactions in plain text. This problem looks difficult to exploit (it requires a man-in-the-middle attack, among other things), but one can't be too sure, so the OpenSSL project has released versions 0.9.7a (with the fix and some new features) and 0.9.6i (with fixes only). See the announcement for details.
Alerts:
Red Hat RHSA-2003:062-11 2003-03-06
SuSE SuSE-SA:2003:011 2003-02-26
Conectiva CLA-2003:570 2003-02-24
Debian DSA-253-1 2003-02-24
Mandrake MDKSA-2003:020 2003-02-21
Trustix 2003-0005 2003-02-20
Gentoo 200302-10 2003-02-20
EnGarde ESA-20030220-005 2003-02-20
OpenPKG OpenPKG-SA-2003.013 2003-02-19

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds