Skip to Content.
Sympa Menu

cacert-sysadm - Re: URGENT OpenSSL flaw Fwd: [Discuss] [Full-disclosure] incorrect integer conversions in OpenSSL can result in memory corruption.

cacert-sysadm AT lists.cacert.org

Subject: CAcert System Admins discussion list

List archive

Re: URGENT OpenSSL flaw Fwd: [Discuss] [Full-disclosure] incorrect integer conversions in OpenSSL can result in memory corruption.


Chronological Thread 
  • From: Guillaume ROMAGNY <guillaume AT cacert.org>
  • To: Wytze van der Raay <wytze AT cacert.org>
  • Cc: cacert-sysadm AT lists.cacert.org, Guillaume ROMAGNY <guillaume AT cacert.org>, Philipp Gühring <pg AT futureware.at>, critical-admin AT cacert.org, iang AT cacert.org, iang AT iang.org
  • Subject: Re: URGENT OpenSSL flaw Fwd: [Discuss] [Full-disclosure] incorrect integer conversions in OpenSSL can result in memory corruption.
  • Date: Fri, 20 Apr 2012 13:23:33 +0200
  • Openpgp: id=EB42B796

Hello Wytze,

On 20/04/2012 11:25, Wytze van der Raay wrote:
On 20.04.2012 01:34, Guillaume ROMAGNY wrote:
 Ha !

Ubuntu security RSS has been faster... 1.25 am today
http://www.ubuntu.com/usn/usn-1424-1/
Faster than what?

Debian released DSA-2454-1 also on April 19, 2012:
   http://www.debian.org/security/2012/dsa-2454

Regards,
-- wytze

Ok, thanks for the quick update of OpenSSL... Reading the report I read "memory corruption" not exploit... but if an exploit was possible so it was rush case.


btw, it seems my RSS Debian Security feed is "slow" compared to Ubuntu (???) but anyway... no big deal

Have a good day.


Best regards,


Guillaume



Attachment: smime.p7s
Description: S/MIME Cryptographic Signature




Archive powered by MHonArc 2.6.16.

Top of Page