Mailing List Archive

OpenSSL Vulnerabilities
>>>>> "Tina" == Tina Bird <tbird@precision-guesswork.com> writes:

Tina> The vendors listed in the CERT advisory on the OpenSSL
Tina> vulnerabilities are all producing server-side software:

Tina> http://www.cert.org/advisories/CA-2002-23.html

Tina> Does anyone know if Netscape, Opera, Internet Explorer or
Tina> any of the other browsers are vulnerable to these issues?

Tina> Thanks in advance -- Tina Bird

Here's how I do it [line may wrap]:

for i in /bin/* /usr/bin/* /sbin/* /usr/sbin/* /usr/X11R6/bin/* /usr/local/bin/* ; do if ldd $i | egrep 'libssl' > /dev/null ; then echo $i ; fi ; done

You could change the list of directories you want to search, or use
the output of a find in the for command. I don't think libcrypto has
issues; if it does, make the argument to egrep
'libcrypto|libssl'.

Regards,

-- Raju
--
Raju Mathur raju@kandalaya.org http://kandalaya.org/
It is the mind that moves
Re: OpenSSL Vulnerabilities [ In reply to ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



- --On Friday, August 02, 2002 09:39:12 AM +0530 Raju Mathur
<raju@linux-delhi.org> wrote:

> Tina> Does anyone know if Netscape, Opera, Internet Explorer or
> Tina> any of the other browsers are vulnerable to these issues?
>
> Tina> Thanks in advance -- Tina Bird
>
> Here's how I do it [line may wrap]:
>
> for i in /bin/* /usr/bin/* /sbin/* /usr/sbin/* /usr/X11R6/bin/*
> /usr/local/bin/* ; do if ldd $i | egrep 'libssl' > /dev/null ; then
> echo $i ; fi ; done
>
> You could change the list of directories you want to search, or use
> the output of a find in the for command. I don't think libcrypto
> has issues; if it does, make the argument to egrep
> 'libcrypto|libssl'.

And

# lsof | egrep 'libcrypto|libssl'

or shorter

# lsof | egrep 'libcrypto|libssl' | awk '{ print$1 }' | sort | uniq

gives an overview, which current running processes must be restarted
afer updating the libraries (and calling ldconfig).

Peter
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)

iD8DBQE9Sieke1eqe5WPQi0RAoN+AKC/ubi3GGYla4a2M8dM0YSuEodTNQCg1UOp
SiVRHrDerHZOdGgRHXWlK4o=
=QhAY
-----END PGP SIGNATURE-----
Re: OpenSSL Vulnerabilities [ In reply to ]
On Friday 02 August 2002 09:33, Peter Bieringer wrote:
> > Here's how I do it [line may wrap]:
> >
> > for i in /bin/* /usr/bin/* /sbin/* /usr/sbin/* /usr/X11R6/bin/*
> > /usr/local/bin/* ; do if ldd $i | egrep 'libssl' > /dev/null ; then
> > echo $i ; fi ; done
> >
> > You could change the list of directories you want to search, or use
> > the output of a find in the for command. I don't think libcrypto
> > has issues; if it does, make the argument to egrep
> > 'libcrypto|libssl'.
>
> And
>
> # lsof | egrep 'libcrypto|libssl'
>
> or shorter
>
> # lsof | egrep 'libcrypto|libssl' | awk '{ print$1 }' | sort | uniq
>
> gives an overview, which current running processes must be restarted
> afer updating the libraries (and calling ldconfig).

IMHO the general problem is recompiling progs which use OpenSSL statically

--
Dimitry
Re: OpenSSL Vulnerabilities [ In reply to ]
>>>>> "Dmitry" == Dmitry Alyabyev <dimitry@al.org.ua> writes:

Dmitry> [.stuff about identifying dynamically linked and running
Dmitry> processes using the openssl libraries snipped]

Dmitry> IMHO the general problem is recompiling progs which use
Dmitry> OpenSSL statically

Are you aware of any such programs?

-- Raju
--
Raju Mathur raju@kandalaya.org http://kandalaya.org/
It is the mind that moves
Re: OpenSSL Vulnerabilities [ In reply to ]
On Monday 05 August 2002 11:12, Raju Mathur wrote:
> >>>>> "Dmitry" == Dmitry Alyabyev <dimitry@al.org.ua> writes:
>
> Dmitry> [.stuff about identifying dynamically linked and running
> Dmitry> processes using the openssl libraries snipped]
>
> Dmitry> IMHO the general problem is recompiling progs which use
> Dmitry> OpenSSL statically
>
> Are you aware of any such programs?

at the moment I'm not but in fact they can be

--
Dimitry