[SECURITY] CVE-2009-3555 SSL Man-In-The-Middle attack - Status update

2009-11-20 Thread Mark Thomas
Overview The purpose of this update is provide information on the current understanding so users are better informed when making decisions regarding risk mitigation for this issue in their environment. Work on the root cause is progressing but is still in a state of flux. Discussion is f

Re: [SECURITY] CVE-2009-3555 SSL Man-In-The-Middle attack

2009-11-13 Thread Filip Hanik - Dev Lists
On 11/09/2009 09:43 AM, Mark Thomas wrote: BIO& NIO connectors using JSSE These connectors are vulnerable when renegotiation is triggered by the client or the server. This is incorrect. NIO doesn't do renegotiation. Instead it sees invalid data and times out. -

[SECURITY] CVE-2009-3555 SSL Man-In-The-Middle attack

2009-11-09 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 A vulnerability in the TLS protocol has recently been made public [1] that allows an attacker to inject arbitrary requests into an TLS stream. The current understanding of the Tomcat developers is as follows: BIO & NIO connectors using JSSE These c