FUDforum
Fast Uncompromising Discussions. FUDforum will get your users talking.

Home » Imported messages » comp.lang.php » Heartbleed bug?
Show: Today's Messages :: Polls :: Message Navigator
Return to the default flat view Create a new topic Submit Reply
Re: Heartbleed bug? [message #185551 is a reply to message #185546] Thu, 10 April 2014 20:56 Go to previous messageGo to previous message
Arno Welzel is currently offline  Arno Welzel
Messages: 317
Registered: October 2011
Karma:
Senior Member
Denis McMahon, 2014-04-10 17:50:

> On Thu, 10 Apr 2014 08:57:54 +0200, Arno Welzel wrote:
>
>> To be precise: If the installed PHP version is linked against OpenSSL
>> then it should be replaced with a patched version of course.
>
> Is simply being linked against the buggy openssl enough to be
> exploitable? As I understand it the openssl code needs to be invoked (eg

No. The bug is only exploitable if you run a SSL/TLS server - which is
possible using PHP.

> https) for the bug to actually expose data.

I don't know what exactly you do with your code. But the opposite -
"it's just PHP, nothing to worry about any library bugs" - is also not
the right way to deal with security problems.


--
Arno Welzel
http://arnowelzel.de
http://de-rec-fahrrad.de
http://fahrradzukunft.de
[Message index]
 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: cURL and response code 302
Next Topic: PHP Parse error: syntax error, unexpected '$sql' (T_VARIABLE) in
Goto Forum:
  

-=] Back to Top [=-
[ Syndicate this forum (XML) ] [ RSS ]

Current Time: Wed Nov 27 14:12:19 GMT 2024

Total time taken to generate the page: 0.06674 seconds