Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » SSL bug compromises secure servers

SSL bug compromises secure servers

by Nikola Strahija on October 12th, 2005 The OpenSSL project has warned of a security bug that could allow attacks on secured servers. The flaw means that an attacker could trick a server into using older, insecure versions of SSL, the project said.


Some sites allow older versions of SSL to be used, but only under particular conditions, such as if a client can't support the more secure SSL 3.0 and TLS 1.0. Researcher Yutaka Oiwa of the Research Centre for Information Security at Japan's National Institute of Advanced Industrial Science and Technology (AIST) first alerted OpenSSL of the problem.

The bug is in an option called SSL_OP_MSIE_SSLV2_RSA_PADDING, intended to help work around interoperability problems. However, the option also disables a verification step needed to prevent active protocol-version rollback attacks, the advisory said.

-An attacker acting as a 'man in the middle' can force a client and a server to negotiate the SSL 2.0 protocol even if these parties both support SSL 3.0 or TLS 1.0, the project said in an advisory on Tuesday. -The SSL 2.0 protocol is known to have severe cryptographic weaknesses and is supported as a fallback only.

The bug affects all versions of OpenSSL up to 0.9.7h and 0.9.8a, and is likely to affect any applications using OpenSSL's SSL/TLS implementation, the group said. Versions 0.9.8a and 0.9.7h have been released to fix the problem. Users can also apply a patch, or disable SSL 2.0 entirely.


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »