D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On Tue, Apr 08, 2014 at 12:45:49PM +0000, Martijn Grooten wrote:
> The vulnerability allows anyone to obtain a chunk of memory from a
> vulnerably server. If that server runs OpenSSH and if OpenSSH stores
> passwords, key phrases and/or private keys in memory, it is affected,
> regardless of the dependency between OpenSSL and OpenSSH.

If you only run SSL/TLS clients, I understand you are still vulnerable
if you connect to a server managed by the attackers. So in practise
you're slightly less vulnerable - and you would be less of a target too.
Still, upgrading is essential.

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq