OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NTBugtraq And NTSecurity Archives: Re: SSL Vulnerability

Re: SSL Vulnerability


Jason Garms (jasongMICROSOFT.COM)
Tue, 6 Jul 1999 11:50:19 -0700


We published a security bulletin and fix for this one year ago today. See
Microsoft security bulletin MS98-002 for more info.

http://www.microsoft.com/security/bulletins/ms98-002.asp

Thanks,
JasonG

-----Original Message-----
From: McAllister James A [mailto:mcallister.jaMELLON.COM]
Sent: Wednesday, June 30, 1999 5:08 PM
To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
Subject: SSL Vulnerability

A Bell-Labs scientist has discovered a flaw in the PKCS#1 technology used in
SSL, which could enable encrypted data to be readable.

For details see:
http://www.rsa.com/rsalabs/pkcs1/
and
http://www.bell-labs.com/news/1998/june/26/1.html

Netscape has a patch out for their web servers, has anyone seen or heard
anything from MS on this?

Jim McAllister, MCSE, MCP+I
Network Systems Administrator
Certus Asset Advisors
San Francisco, CA

Any opinions expressed are my own and do not necessarily reflect those of my
employer.



This archive was generated by hypermail 2.0b3 on Tue Jul 06 1999 - 00:34:07 CDT