|
|
| |
|
| |
openssl: remote code execution
| Package(s): | openssl |
CVE #(s): | CVE-2010-3864
|
| Created: | November 17, 2010 |
Updated: | November 30, 2010 |
| Description: |
The OpenSSL project has issued an advisory of a race condition which exists
in versions prior to 0.9.8p or 1.0.0b. Successfully exploiting this race
can enable a remote attacker to inject code into a server using OpenSSL.
It's worth noting, though, that only servers which are
(1) multi-threaded, and (2) using OpenSSL's internal caching are
vulnerable. So, in particular, Apache servers are not at risk.
See this advisory for more information. |
| Alerts: |
|
( Log in to post comments)
|
|
|