* Posts by mark cox

3 publicly visible posts • joined 13 May 2008

OpenSSL updated to kill code-execution bug

mark cox

Sky not falling yet.

We think it's unlikely to be usefully exploitable:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2010-3864#c7

SSL spoof bug still haunts IE, Safari, Chrome

mark cox

Actual timeline

We actually had advance notice to be able to fix this issue so quickly after disclosure:

http://www.awe.com/mark/blog/20091007.html

Debian fixes serious crypto bug

mark cox

Doesn't affect OpenSSL upstream or other vendors

"Another has suggested the bug resides within OpenSSL itself and dates from May 2006,"

This is not true, this issue does not affect upstream OpenSSL or any vendors that are not derived from Debian.