Re: FreeBSD-SA-04:05.openssl question

看板FB_security作者時間22年前 (2004/03/19 06:02), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串6/7 (看更多)
On Wed, Mar 17, 2004 at 06:20:09PM -0800, Rostislav Krasny wrote: > Do you imply that applications with ability to use Kerberos > ciphersuites are impossible to be implemented for current versions of FreeBSD? The base system OpenSSL has no support for implementing the Kerberos ciphersuites (the OpenSSL code is extremely MIT Kerberos specific). The ports system OpenSSL appears to have no support, either. If one compiles OpenSSL oneself, *and* has MIT Kerberos, *and* enables the Kerberos options, *and* has all ciphersuites (or at least the Kerberos ciphersuites) specified in your application's configuration, then you might be affected. But that has nothing to do with FreeBSD. Thus, answering your question again: Isn't FreeBSD vulnerable to the second "Out-of-bounds read affects Kerberos ciphersuites" security problem? No, FreeBSD is not. Cheers, -- Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #10MXo900 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #10MXo900 (FB_security)