Latest news
Advisory #1 consist of the following vulnerabilities:
1. The client master key in SSL2 could be oversized and overrun a buffer. This vulnerability was also independently discovered by consultants at Neohapsis (http://www.neohapsis.com/) who have also demonstrated that the vulerability is exploitable. Exploit code is not available at this time.
2. The session ID supplied to a client in SSL3 could be oversized and overrun a buffer.
3. The master key supplied to an SSL3 server could be oversized and overrun a stack-based buffer. This issues only affects OpenSSL 0.9.7 before 0.9.7-beta3 with Kerberos enabled.
4. Various buffers for ASCII representations of integers were too small on 64 bit platforms.
Advisory #2 says that the ASN1 parser can be confused by supplying it with certain invalid encodings.
Both advisories can be found in the mentioned OpenSSL Security Advisory available over here:
http://www.net-security.org/vuln.php?id=1916

CERT Advisory CA-2002-23 - Multiple Vulnerabilities In OpenSSL
http://www.net-security.org/advisory.php?id=880
Systems Affected:
* OpenSSL prior to 0.9.6e, up to and including pre-release 0.9.7-beta2
* OpenSSL pre-release 0.9.7-beta2 and prior with Kerberos enabled
* SSLeay library

Vendor security advisories:
Red Hat Security Advisory - Updated openssl packages fix remote vulnerabilities
http://www.net-security.org/advisory.php?id=890
EnGarde Secure Linux Advisory - Several vulnerabilities in the openssl library
http://www.net-security.org/advisory.php?id=889
Debian Security Advisory - Multiple OpenSSL problems
http://www.net-security.org/advisory.php?id=888
SuSE Security Announcement - openssl
http://www.net-security.org/advisory.php?id=884
Mandrake Linux Security Advisory - openssl
http://www.net-security.org/advisory.php?id=882

Solutions:
Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







