Oracle Issues High Risk SSL Security Alert
Oracle has issued an alert (PDF) detailing high risk security holes affecting all SSL products in the Oracle9i Application Server, the Oracle9i and Oracle8i Database Servers, and Oracle HTTP server. "Any client that is able to access the server may exploit the vulnerabilities," the company said in its alert.
The patches address security issues in OpenSSL that were outlined on our site last month, and originally published by NISCC on Sept. 30. Fixes for these problems are available in the latest versions of OpenSSL (0.9.6k and 0.9.7c).
OpenSSL is an open source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a general purpose cryptography library.
Topically, the host involved in todays fraud attack on National Westminster was, according to the published Apache module line running a vulnerable version of OpenSSL.
Posted by Rich Miller at 8 December 2003
in Security
|
Print this Page
| Rackspace Managed Hosting - Web Hosting - Hosting | Swishmail.com Business Email Hosting | Compare the Best Web Hosting Companies |
| INetU Managed Hosting - Dedicated Servers | Windows Dedicated Servers from Server Intellect | Reseller hosting Managed dedicated server Ahosting |
| Business Web Hosting Services - webhosting.uk.com | Web Hosting - Dedicated Servers & VPS Hosting | Managed Hosting - PCI Compliance by NeoSpire |
| SEO: Free SEO Analysis From SEO Consult | Search Engine Optimization : Results Based SEO | |
Advertising on Netcraft
Copyright © Netcraft Ltd 2010. All Rights Reserved.
Digg
Slashdot
Reddit
StumbleUpon
Delicious
Technorati