SSL and TLS Vulnerable to Man-in-the-middle Attacks
View Original Post | US-CERT Current Activity | --> Latest Alerts
Date: 2009/11/6 18:01:00
Views: 21 | Transfer
Date: 2009/11/6 18:01:00
Views: 21 | Transfer
US-CERT is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream.
US-CERT encourages OpenSSL users and administrators to review the OpenSSL 0.9.81 release and apply any updates.
US-CERT has not received any reports of active exploitation and will continue to provide additional information as it becomes available.
The comments are owned by the poster. We aren't responsible for their content.




