[OpenSSL Advisory] Denial of Service in ASN.1 parsing

2003-11-04 Thread Mark J Cox
-BEGIN PGP SIGNED MESSAGE- OpenSSL Security Advisory [4 November 2003] Denial of Service in ASN.1 parsing == Previously, OpenSSL 0.9.6k was released on the 30 September 2003 to address various ASN.1 issues. The issues were found using a test suite from NI

[OpenSSL Advisory] Vulnerabilities in ASN.1 parsing

2003-10-03 Thread Mark J Cox
-BEGIN PGP SIGNED MESSAGE- OpenSSL Security Advisory [30 September 2003] Vulnerabilities in ASN.1 parsing NISCC (www.niscc.gov.uk) prepared a test suite to check the operation of SSL/TLS software when presented with a wide range of malformed client certif

Re: CSSA-2003-007.0 Advisory withdrawn.

2003-02-18 Thread Mark J Cox
-BEGIN PGP SIGNED MESSAGE- Just to clarify this a bit further, the mod_dav module for Apache is not vulnerable to the format string vulnerability (as outlined in the original advisory from SCO, CAN-2002-0842) mod_dav contains code that logs various errors and uses ap_log_rerror() to do so

Apache 2.0 vulnerability affects non-Unix platforms

2002-08-09 Thread Mark J Cox
-BEGIN PGP SIGNED MESSAGE- For Immediate Disclosure === SUMMARY Title: Apache 2.0 vulnerability affects non-Unix platforms Date: 9th August 2002 Revision: 2 Product Name: Apache HTTP server 2.0 OS/Platform: Windows, OS2, Netware Perm