Dejkala
No Result
View All Result
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
No Result
View All Result
Dejkala
No Result
View All Result
Home Latest update

OpenSSL 3 patch, once Heartbleed-level “critical,” arrives as a lesser “high”- Dejkala

by hasibul
November 1, 2022
in Latest update
0
0
VIEWS
Share on FacebookShare on Twitter


The fallout of an OpenSSL vulnerability, initially listed as
Enlarge / The fallout of an OpenSSL vulnerability, initially listed as “critical,” should be much less severe than that of the last critical OpenSSL bug, Heartbleed.

An OpenSSL vulnerability once signaled as the first critical-level patch since the Internet-reshaping Heartbleed bug has just been patched. It ultimately arrived as a “high” security fix for a buffer overflow, one that affects all OpenSSL 3.x installations, but is unlikely to lead to remote code execution.

OpenSSL version 3.0.7 was announced last week as a critical security fix release. The specific vulnerabilities (now CVE-2022-37786 and CVE-2022-3602) had been largely unknown until today, but analysts and businesses in the web security field hinted there could be notable problems and maintenance pain. Some Linux distributions, including Fedora, held up releases until the patch was available. Distribution giant Akamai noted before the patch that half of their monitored networks had at least one machine with a vulnerable OpenSSL 3.x instance, and among those networks, between 0.2 and 33 percent of machines were vulnerable.

But the specific vulnerabilities—limited-circumstance, client-side overflows that are mitigated by the stack layout on most modern platforms—are now patched, and rated as “High.” And with OpenSSL 1.1.1 still in its long-term support phase, OpenSSL 3.x is not nearly as widespread.

Malware expert Marcus Hutchins points to an OpenSSL commit on GitHub that details the code issues: “fixed two buffer overflows in puny code decoding functions.” A malicious email address, verified within an X.509 certificate, could overflow bytes on a stack, resulting in a crash or potentially remote code execution, depending on the platform and configuration.

Advertisement

But this vulnerability mostly affects clients, not servers, so the same kind of Internet-wide security reset (and absurdity) of Heartbleed won’t likely follow. VPNs that utilize OpenSSL 3.x could be affected, for example, and languages like Node.js. Cybersecurity expert Kevin Beaumont points out that the stack overflow protections in most Linux distributions’ default configurations should prevent code execution.

What changed between the critical-level announcement and high-level release? OpenSSL’s security team writes in a blog post that in roughly a week’s time, organizations tested and provided feedback. On some Linux distributions, the 4-byte overflow possible with one attack overwrote an adjacent buffer not yet used, and so could not crash a system or execute code. The other vulnerability only allowed an attacker to set the length of an overflow, not the content.

So while crashes are still possible, and some stacks could be arranged in ways that make remote code execution possible, it’s not likely or easy, which downgrades the vulnerabilities to “high.” Users of any 3.x OpenSSL implementation, however, should patch as soon as possible. And everybody should be looking out for software and OS updates that may patch these issues in various subsystems.

Monitoring service Datadog, in a good summary of the issue, notes that its security research team was able to crash a Windows deployment using an OpenSSL 3.x version in a proof of concept. And while Linux deployments are not likely exploitable, “an exploit crafted for Linux deployments” could still emerge.

The National Cyber Security Centrum of the Netherlands (NCSL-NL) has a running list of vulnerable software to the OpenSSL 3.x exploit. Numerous popular Linux distributions, virtualization platforms, and other tools are listed as either vulnerable or under investigation.




Related

ShareTweetShare

Related Posts

InMotion Hosting review: Everything you need to host a website- Dejkala
Latest update

InMotion Hosting review: Everything you need to host a website- Dejkala

March 23, 2023
FTC wants to make it easier for you to cancel subscriptions- Dejkala
Latest update

FTC wants to make it easier for you to cancel subscriptions- Dejkala

March 23, 2023
Diablo 4 might brick your RTX 3080 Ti graphics card- Dejkala
Latest update

Diablo 4 might brick your RTX 3080 Ti graphics card- Dejkala

March 23, 2023
Montenegro's Interior Minister Filip Adzic says Terraform Labs co-founder Do Kwon has been arrested at the Podgorica airport with falsified documents (CoinDesk)- Dejkala
Latest update

Montenegro's Interior Minister Filip Adzic says Terraform Labs co-founder Do Kwon has been arrested at the Podgorica airport with falsified documents (CoinDesk)- Dejkala

March 23, 2023
How and where to buy refurbished tech online- Dejkala
Latest update

How and where to buy refurbished tech online- Dejkala

March 23, 2023
The FTC proposes a "click to cancel" ban on difficult-to-cancel subscriptions, including making canceling as simple as subscribing by using the same method (Adi Robertson/The Verge)- Dejkala
Latest update

The FTC proposes a "click to cancel" ban on difficult-to-cancel subscriptions, including making canceling as simple as subscribing by using the same method (Adi Robertson/The Verge)- Dejkala

March 23, 2023
Next Post
Some of our favorite gaming mice are up to 47 percent off at Amazon- Dejkala

Some of our favorite gaming mice are up to 47 percent off at Amazon- Dejkala

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Recommended

Elon Musk says Twitter has had a "massive" revenue drop due to activist groups pressuring advertisers, despite doing "everything" to "appease the activists" (Wall Street Journal)- Dejkala

Elon Musk says Twitter has had a "massive" revenue drop due to activist groups pressuring advertisers, despite doing "everything" to "appease the activists" (Wall Street Journal)- Dejkala

November 4, 2022
Tesla to recall 362,758 cars because Full Self Driving Beta is dangerous- Dejkala

Tesla to recall 362,758 cars because Full Self Driving Beta is dangerous- Dejkala

February 16, 2023
Airbnb will improve transparency around pricing- Dejkala

Airbnb will improve transparency around pricing- Dejkala

November 7, 2022
A look at the digital asset diehards at Art Basel in Miami, who tried to ignore the fallout from FTX's collapse even as FTX merch remained, hidden in storerooms (Bloomberg)- Dejkala

A look at the digital asset diehards at Art Basel in Miami, who tried to ignore the fallout from FTX's collapse even as FTX merch remained, hidden in storerooms (Bloomberg)- Dejkala

December 7, 2022
Meta AI and Papers with Code unveil Galactica, an open source LLM for generating literature reviews, wiki articles, lecture notes, and more on scientific topics (Matthias Bastian/The Decoder)- Dejkala

Meta AI and Papers with Code unveil Galactica, an open source LLM for generating literature reviews, wiki articles, lecture notes, and more on scientific topics (Matthias Bastian/The Decoder)- Dejkala

November 16, 2022
Singapore wants all critical infrastructures to be ready for cyber threats- Dejkala

Singapore wants all critical infrastructures to be ready for cyber threats- Dejkala

December 14, 2022
InMotion Hosting review: Everything you need to host a website- Dejkala

InMotion Hosting review: Everything you need to host a website- Dejkala

March 23, 2023
FTC wants to make it easier for you to cancel subscriptions- Dejkala

FTC wants to make it easier for you to cancel subscriptions- Dejkala

March 23, 2023
Diablo 4 might brick your RTX 3080 Ti graphics card- Dejkala

Diablo 4 might brick your RTX 3080 Ti graphics card- Dejkala

March 23, 2023

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Pages

  • About Us
  • Banking & loan
  • Car’s & Bike’s
  • Contact Us
  • Games
  • Home
  • Home 2
  • Privacy Policy
  • Tech

© 2022 Dejkala

No Result
View All Result
  • Homepages
    • Home – Layout 1
    • Home – Layout 2

© 2022 Dejkala