OpenSSL Hit By New High Severity Security Issue

Written by Michael Larabel in Linux Security on 16 February 2017 at 12:06 PM EST. 13 Comments
LINUX SECURITY
OpenSSL has been hit by another "high" severity security vulnerability.

While OpenSSL's code has improved in the three years since the Heartbleed vulnerability, new issues continue to come up for this important open-source project. From CVE-2017-3733:
Encrypt-Then-Mac renegotiation crash (CVE-2017-3733)
====================================================

Severity: High

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL to crash (dependent on ciphersuite). Both clients and servers are affected.

OpenSSL 1.1.0 users should upgrade to 1.1.0e
The good news is that OpenSSL 1.0.2 isn't affected by this issue but this time around is just for OpenSSL 1.1 (pre-1.1.0e).
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week