OpenSSL CVE-2010-5298 / CVE-2014-0198(ubuntu.com)
ubuntu.com
OpenSSL CVE-2010-5298 / CVE-2014-0198
http://www.ubuntu.com/usn/usn-2192-1/
2 comments
This doesn't seem all that important. There are numerous bugs around most software out there which can cause it to crash. It's not good, but it's also not the worst one out there.
If it was that bad, it would have been fixed earlier. It was reported first in 2010: https://rt.openssl.org/Ticket/Display.html?id=2167&user=gues...
It was also fixed a few weeks ago.
Edit: Just noticed that the openssl bug tracker passes the username and password in the URL. Oh dear...
If it was that bad, it would have been fixed earlier. It was reported first in 2010: https://rt.openssl.org/Ticket/Display.html?id=2167&user=gues...
It was also fixed a few weeks ago.
Edit: Just noticed that the openssl bug tracker passes the username and password in the URL. Oh dear...
At least no google results for anything other than guest show up.
For a security project I find their lack of security shocking.
r/netsec threads on CVE-2010-5298:
http://www.reddit.com/r/netsec/comments/22whnm/openssl_useaf...
http://www.reddit.com/r/netsec/comments/23pggy/all_versions_...
RH Response: https://access.redhat.com/security/cve/CVE-2010-5298 see the BZ links closed as "not exploitable"
http://www.reddit.com/r/netsec/comments/22whnm/openssl_useaf...
http://www.reddit.com/r/netsec/comments/23pggy/all_versions_...
RH Response: https://access.redhat.com/security/cve/CVE-2010-5298 see the BZ links closed as "not exploitable"
The 4 year old CVE-2010-5298 is described as
"Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment."
The more concerning part obviously being data injection.
CVE-2014-0198 is described as "A null pointer dereference bug was discovered in so_ssl3_write(). An attacker could possibly use this to cause OpenSSL to crash, resulting in a denial of service."
Clearly in the wake of heartbleed OpenSSL is undergoing serious scrutiny; and hopefully this results in a wider attitude change:
Just because something is opensource doesn't mean someone has audited the code for you, it's there you can read it yourself ... 20:20 hindsight eh?
Ah well sleep is truely for quitters ... headdesk