Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Mar 2004 07:38:37 -0600
From:      "Jacques A. Vidrine" <nectar@FreeBSD.org>
To:        Rostislav Krasny <rosti_bsd@yahoo.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: FreeBSD-SA-04:05.openssl question
Message-ID:  <20040318133837.GB11791@lum.celabo.org>
In-Reply-To: <20040318022009.52877.qmail@web14804.mail.yahoo.com>
References:  <xzpn06fkm5d.fsf@dwp.des.no> <20040318022009.52877.qmail@web14804.mail.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Mar 17, 2004 at 06:20:09PM -0800, Rostislav Krasny wrote:
> Do you imply that applications with ability to use Kerberos
> ciphersuites are impossible to be implemented for current versions of FreeBSD?

The base system OpenSSL has no support for implementing the Kerberos
ciphersuites (the OpenSSL code is extremely MIT Kerberos specific).

The ports system OpenSSL appears to have no support, either.

If one compiles OpenSSL oneself, *and* has MIT Kerberos, *and* enables
the Kerberos options, *and* has all ciphersuites (or at least the
Kerberos ciphersuites) specified in your application's configuration,
then you might be affected.  But that has nothing to do with FreeBSD.
Thus, answering your question again:

  Isn't FreeBSD vulnerable to the second "Out-of-bounds read affects
  Kerberos ciphersuites" security problem?

No, FreeBSD is not.

Cheers,
-- 
Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040318133837.GB11791>