Three open-source vulnerabilities

The OpenSSL Project has released patches to fix three vulnerabilities. The first two deal with buffer problems in OpenSSL in all versions up to and including 0.9.6j and 0.9.7b, and all versions of SSLeay. These vulnerabilities if exploited could lead to a DOS attack by crashing the system.  Potentially more serious is the third vulnerability which exists in versions of the widely used Sendmail package prior to 8.12.10.  Vendors who use the package include HP, IBM and Red Hat. This buffer overflow flaw could allow a remote attacker to execute arbitrary code with root privileges.  Patches are available here: http://www.cert.org/advisories/CA-2003-24.html http://www.cert.org/advisories/CA-2003-25.html

Related posts:

  1. Open source CVS vulnerability
  2. Another SendMail vulnerability
  3. Unix CDE vulnerability
  4. Trojan horse in distributed version of Sendmail source
  5. Apache/Linux worm exploits vulnerability
= Paid content

All Windows Secrets articles posted on 2003-10-16: