public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Alan McKinnon <alan.mckinnon@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Re: 'Heartbleed' bug
Date: Fri, 11 Apr 2014 00:59:07 +0200	[thread overview]
Message-ID: <5347223B.5030208@gmail.com> (raw)
In-Reply-To: <li77hc$fko$1@ger.gmane.org>

On 11/04/2014 00:55, walt wrote:
> On 04/09/2014 05:06 PM, Joseph wrote:
>> Is gentoo effected by this new 'Heartbleed' bug?
>>
>> "The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library...."
>>
>> http://heartbleed.com/
> 
> This topic was discussed in my favorite podcast, http://twit.tv/sn
> 
> Steve Gibson explained that the heartbeat feature was introduced in openssl to
> allow *UDP* connections to mimic the 'keepalive' function of the TCP protocol.
> 
> IIRC Steve didn't explain how UDP bugs can compromise TCP connections.
> 
> Anyone here really understand the underlying principles?  If so, please explain!
> 
> Thanks.
> 
> 
> 
> 
> 


UDP is not compromising TCP connections.
The software bug allows malicious connecting code to determine the
contents of memory, which is in use by sshd. How that memory got to be
there is irrelevant.

There are many lengthy discussions on the internet on how this vuln
works. You should read them.

-- 
Alan McKinnon
alan.mckinnon@gmail.com



  reply	other threads:[~2014-04-10 22:59 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-04-10  0:06 [gentoo-user] 'Heartbleed' bug Joseph
2014-04-10  0:13 ` Ralf
2014-04-10  0:32 ` Michael Orlitzky
2014-04-10  5:48   ` Pavel Volkov
2014-04-10  9:03     ` Adam Carter
2014-04-10  9:53       ` Ján Zahornadský
2014-04-10 10:52         ` Matthew Finkel
2014-04-10 10:51           ` Nilesh Govindrajan
2014-04-10 11:00             ` Randolph Maaßen
2014-04-10 11:06               ` Ján Zahornadský
2014-04-10 11:06           ` Neil Bothwick
2014-04-10 10:42 ` Marc Joliet
2014-04-10 22:55 ` [gentoo-user] " walt
2014-04-10 22:59   ` Alan McKinnon [this message]
2014-04-10 23:38     ` Chris Walters
2014-04-10 23:37   ` Matthew Finkel
2014-04-10 23:42   ` Ralf
2014-04-11  8:05   ` Philip Webb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5347223B.5030208@gmail.com \
    --to=alan.mckinnon@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox