CVE-2014- and OpenSSL?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



So Adam Langley writes "SSLv3 decoding function was used with TLS,
then the POODLE attack would work, even against TLS connections." on
his the latest POODLE affecting TLS 1.x.
(https://www.imperialviolet.org/).

I also received a notification from Symantec's DeepSight, that states:
"OpenSSL CVE-2014-8730 Man In The Middle Information Disclosure
Vulnerability".

However, I could not find more information on OpenSSL's web-site about
POODLE-biting-again. Did I miss any notification? Thanks.

-Amarendra


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux