OpenSSL fixes high-severity flaw that allows hackers to crash servers
26 Mar
2021
26 Mar
'21
noon
'On Thursday, OpenSSL maintainers disclosed and patched a vulnerability that causes servers to crash when they receive a maliciously crafted request from an unauthenticated end user. CVE-2021-3449, as the denial-of-server vulnerability is tracked, is the result of a null pointer dereference bug. Cryptographic engineer Filippo Valsorda, said on Twitter that the flaw could probably have been discovered earlier than now.
“Anyway, sounds like you can crash most OpenSSL servers on the Internet today,” he added.'
-- source: https://arstechnica.com/gadgets/2021/03/openssl-fixes-high-severity-flaw-tha...
Cheers, Peter
--
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 577-5304
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
1205
Age (days ago)
1205
Last active (days ago)
0 comments
1 participants
participants (1)
-
Peter Reutemann