Firewall Wizards mailing list archives

Re: Looking for "lease based popper access"


From: "Steven M. Bellovin" <smb () research att com>
Date: Wed, 15 Dec 1999 11:04:05 -0500

In message <Pine.LNX.4.05.9912131147530.6877-100000 () darkstar sysinfo com>, "R. 
DuFresne" writes:

Has there been a patch released by the RSA folks to deal with it's recent
failing?  The impact of the RSA buffer overflow is that it affects all
applications built around it's core, this includes ssh, ssl enabled
webservers, etc..  Yep all those aplications built with RSA are now
exploitable, so, has a pacht been released that addresses this and allows
folks to patch RSAREF then rebuild all the applications that use it?

See CERT Advisory CA-99-15, http://www.cert.org/advisories/CA-99-15-RSAREF2.html, 
for a pointer to a patch.

                --Steve Bellovin




Current thread: