• 请不要在回答技术问题时复制粘贴 AI 生成的内容
p2p
V2EX  ›  程序员

openssl CCS Injection Vulnerability 已存在 16 年之久

  •  
  •   p2p · Jun 6, 2014 · 3854 views
    This topic created in 4443 days ago, the information mentioned may be changed or developed.
    OpenSSL’s ChangeCipherSpec processing has a serious vulnerability. This vulnerability allows malicious intermediate nodes to intercept encrypted data and decrypt them while forcing SSL clients to use weak keys which are exposed to the malicious nodes.



    A. Affected Versions:

    OpenSSL 1.0.1 through 1.0.1g
    OpenSSL 1.0.0 through 1.0.0l
    all versions before OpenSSL 0.9.8y


    B. Not Affected Versions:

    OpenSSL 1.0.1h
    OpenSSL 1.0.0m
    OpenSSL 0.9.8za

    http://ccsinjection.lepidum.co.jp/
    2 replies    2014-06-06 13:20:20 +08:00
    windyboy
        1
    windyboy  
       Jun 6, 2014
    看来还要改
    io565
        2
    io565  
       Jun 6, 2014 via iPhone
    openssl干脆推翻重建吧 再来几个漏洞google岂不是都要放弃治疗了
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   1522 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 24ms · UTC 16:34 · PVG 00:34 · LAX 09:34 · JFK 12:34
    ♥ Do have faith in what you're doing.