Internet

OpenSSL Certificates Paralyze Servers and Clients

The OpenSSL encryption software appears to have a dangerous vulnerability. Using crafted OpenSSL certificates, it is possible to attack servers and clients. The developers have already released new versions that fix the bug, a warning according to the OpenSSL developers, servers and clients can go into an infinite loop when loading certain TLS certificates. The bug is in the BN-mod-sqrt() function and allows hackers to perform a DOS attack. This requires the use of TLS certificates or private keys with elliptic curve parameters. It is unclear whether the bug is already being actively exploited in practice.

While DOS attacks can cause server failures, the vulnerability cannot do widespread damage. It is not a vulnerability that would allow malicious code to be run on third-party systems. However, servers can become paralyzed and financial damage can occur. The vulnerability is called CVE-2022-0788 and has a high threat level. The bug was originally discovered by Google security researcher Tavis Ormandy.

Administrators need to update their software

If you are using OpenSSL, you should update the installed software as soon as possible. In addition to version 1.1.1n, version 3.0.2 must also be secure. Premium Support customers can download the 1.0.2zd release. OpenSSL version 1.1.0 is also affected by the issue. However, the builds are no longer provided with updates. Since OpenSSL is used in many programs, many apps are likely to be at risk. The developers must therefore respond quickly and provide updates.


Recent Posts

Apple could be banned from buying Chinese memory chips

Due to the global shortage of memory chips, Apple is looking for new suppliers in…

8 hours ago

Assassin’s Creed Hexe: New leak reveals information about gameplay, price and much more.

Ubisoft is working on the next big title in its well-known video game series with…

8 hours ago

Steam games on SSD: hobbyist builds his own retro PC cartridges

A PC gamer has found a way to bring the feel of classic cartridges into…

8 hours ago

Apple lawsuit against OpenAI: Embarrassing email glitch escalated the dispute

Apple is suing OpenAI for allegedly stealing secret hardware information. Current documents now show the…

8 hours ago

Sonos fixes controversial app: Update brings back tab navigation

Sonos is currently releasing a new app update: The classic tab navigation returns, speakers can…

8 hours ago

Zoom users beware: Serious vulnerability in the Windows client

Meeting platform Zoom has warned of a serious security flaw in its Windows software that…

8 hours ago