Tech Brewed Tech Brief 2923 - podcast episode cover

Tech Brewed Tech Brief 2923

Feb 09, 20232 minSeason 3Ep. 7
--:--
--:--
Download Metacast podcast app
Listen to this episode in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episode description

Send us a text


OpenSSL is like a lock to keep your information safe and secure. Recently, someone discovered a way to trick the lock and get access to your information. To ensure this doesn't happen, they need to upgrade the lock. So, they have to update OpenSSL, so that bad people can't get through the lock.

Subscribe to the weekly tech newsletter at https://gregdoig.com

Transcript

Greg Doig

Here's an update for open SSL and it was updated on their website@openssl.org on February 7th, 2023. For those not familiar, the Open SSL project is a toolkit that provides cryptographic tools and secure communications software. It is managed by the open SSL technical. And the open SSL management Committee and is available under an Apache style license, which allows commercial and non-commercial use. Subject to certain conditions. Users can access the source news and more.

Using the community page. Again, at www.open ssl.org G open SSL is like a lock to keep your information safe and secure. Recently someone discovered a way to trick the lock and get access to your inform. To make sure this doesn't happen, they need to upgrade the lock. So they have to update open SSL so that the bad people can't get through the lock.

So what Open SSL did is they released an advisory warning on February 7th that a type confusion vulnerability was discovered in the X 400 address processing inside in X 5 0 9 General. Which could put users at risk of memory, leakage, or denial of service attacks if C R L checking is enabled. So to address this vulnerability, open SSL 3.0 users should upgrade to open SSL 3.08 and open SSL one point one.one and 1 0 2. Users should upgrade to the appropriate version on their.

The vulnerability was reported by David Benjamin from Google, and the fix was developed by Hugo Land Out. So if you're responsible for open SSL on any device that you or your company may use, get to the page and get the update as your tech brute tech brief from today.

Transcript source: Provided by creator in RSS feed: download file
For the best experience, listen in Metacast app for iOS or Android