4 ms·
So, this exploit allows for a Denial of Service Attack. While this does mean a single person could bring down your site, it does not appear that it will allow
by techscruggs 12y ago
So, this exploit allows for a Denial of Service Attack. While this does mean a single person could bring down your site, it does not appear that it will allow someone to gain access to your server via this exploit.
- techscruggs 12y agoAlso, this is only an issue if you are running version 1.0.2. It doesn't affect any other version.
- sjs382 12y agoOther CVEs in the bulletin affect other versions.
- orblivion 12y agoThat's just the first of two high severity, right? The other sounds like Freakattack, but upgraded in severity. Perhaps others could correct me.
- danieldk 12y agoBut the second high severity vulnerability was already known and fixed in most systems. E.g. Debian: https://www.debian.org/security/2015/dsa-3125 https://www.debian.org/security/2015/dsa-3125 If this isn't patched on somebodies machine yet, they're doing something wrong ;). (Has Apple patched this yet?)
- orblivion 12y agoWhen Freak Attack came out, all I ever saw was about how to manually disable the export ciphers. So they finally come out with a fix to disallow them in the program?
- baby 12y agoIt is exactly that