On last.fm: Exclusive interview with Phoenix
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Mar 18, 2004 12:32:00 AM

The group behind OpenSSL, a widely used open-source Web security program, released two patches for security flaws to block potential denial-of-service attacks, the organization's developers said on Wednesday.

The flaws affect more than Linux systems that have the software installed. They could also hobble many routers


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


and network devices that incorporate the software. Cisco Systems released an advisory on Wednesday, saying its PIX firewall devices and some routers could be affected.

OpenSSL is an open implementation of Secure Sockets Layer (SSL) encryption, which is used by almost all Web browsers as a way to secure data that travels over the public Internet. The software also forms the basis of a popular component of the Apache Web server, which accounts for more than two-thirds of the servers on the Internet.

The flaws don't give an attacker the opportunity to take control of a computer or a device, but they do create the possibility for specially crafted data to crash the software. Such a denial-of-service attack could stop users


Get Up to Speed on...
Open source
Get the latest headlines and
company-specific news in our
expanded GUTS section.


from logging in to a server and prevent administrators from managing network devices. In some cases, the flaws will crash the device, causing wider network outages, according to several advisories.

A survey conducted last November found that nearly half of the Web servers involved in the study ran a version of OpenSSL that hadn't been recently patched. A flaw in the Web server component based of OpenSSL was responsible for allowing the Linux Slapper worm to spread in September 2002.

Red Hat and Novell's SuSE Linux subsidiary both ship Linux systems that incorporate OpenSSL.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 1 Talkback(s)
Open Serial Specail Layer and technology  Taco Warrior | 03/17/04

What do you think?

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline