Home > Security News > Multiple Cisco products among those clobbered by OpenSSL flaw
Security News:
EMAIL THIS

Multiple Cisco products among those clobbered by OpenSSL flaw

By Edmund X. DeJesus, Contributing Writer
18 Mar 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Cisco switches, routers and firewalls are vulnerable to attack due to a problem in OpenSSL that has other software vendors scrambling to cope. Failure to deal with the problem can leave systems open to remote denial of service (DoS).

Multiple products with HTTPS servers running OpenSSL are vulnerable to a remote DoS attack. OpenSSL is an open source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols for security and cryptographic applications.

For more information

Click here for the Cisco advisory or here for the fix.

For information about other products affected by the flaw, see below:

Debian
EnGarde
FreeBSD
Gentoo

Kerberos
Mandrake
Red Hat
Slackware
SuSE

By using a specially formed SSL/TLS handshake, a vulnerability in the do_change_cipher_spec function in OpenSSL (versions 0.9.6c through 0.9.6k, and 0.9.7a through 0.9.7c) can allow a remote attacker to force a null-pointer assignment that crashes or resets the hardware, causing a DoS.

The problem affects Cisco IOS, Cisco PIX, Cisco Firewall Services Module for the Cisco Catalyst, Cisco MDS Multilayer Switch, Cisco Content Service Switch, Cisco Global Site Selector, CiscoWorks Common Services, CiscoWorks Common Management Foundation and Cisco Access Registrar (see Cisco site for version details).

Devices that use Secure Shell (SSH) instead of OpenSSL for secure access aren't affected by this vulnerability.

Limited workarounds are possible, including restricting access to the HTTPS server and disabling the SSL server or service. Cisco has provided fixes for these problems.

Cisco isn't alone in dealing with the OpenSSL problem. Vendors including Debian, EnGarde, FreeBSD, Gentoo, Kerberos, Mandrake, Red Hat, Slackware and SuSE are all struggling to deal with the consequences of the OpenSSL problem.

Tags: SSL and TLS VPN SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SSL and TLS VPN Security
Expert calls SSL protocol vulnerability a non issue
How SSL-encrypted Web connections are intercepted
Best Remote Access Products
How to set up a split-tunnel VPN in Windows Vista
Securing the intranet with remote access VPN security
A short enterprise VPN deployment guide
Creating an SSL connection between servers
Can S/MIME, XML and IPsec operate in one protocol layer?
Can secure USB devices prevent man-in-the middle attacks
How to secure SSL following new man-in-the-middle SSL attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Secure Shell  (SearchSecurity.com)
Secure Sockets Layer  (SearchSecurity.com)
server accelerator card  (SearchSecurity.com)
SSL VPN  (SearchSecurity.com)
Transport Layer Security  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts