[Cryptography] It's GnuTLS's turn: "Critical new bug in crypto library leaves Linux, apps open to drive-by attacks"

Tom Mitchell mitch at niftyegg.com
Tue Jun 3 21:43:56 EDT 2014


On Tue, Jun 3, 2014 at 10:57 AM, Jerry Leichter <leichter at lrw.com> wrote:

> "A recently discovered bug in the GnuTLS cryptographic code library puts
> users of Linux and hundreds of other open source packages at risk of
> surreptitious malware attacks until they incorporate a fix developers
> quietly pushed out late last week."
>
>
This has large implications for  embedded software....
Appliances are notoriously long lived and not profitable to maintain.
I have numerous wifi routers that can only be used in islolation.
I have a growing pile of phones and tablet hardware that are no
longer getting updates from the vendor....  In some cases AT&T
blocks Samsung from updating Samsung designed hardware.

They are locked or closed source and closed hardware so I cannot ---.

-- 
  T o m    M i t c h e l l
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20140603/d450fc7c/attachment.html>


More information about the cryptography mailing list