Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-08 Thread David H
RHEL update just released, hopefully CentOS soon: https://rhn.redhat.com/errata/RHSA-2014-0376.html On Mon, Apr 7, 2014 at 8:10 PM, Kirils Solovjovs < kirils.solovj...@kirils.com> wrote: > We are doomed. > > Description: http://www.openssl.org/news/vulnerabilities.html > Article dedicated to the

Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-08 Thread David H
I'm curious if anyone has noticed issues connecting to remote hosts after installing the RHEL/CentOS patch? For example, the CyberSource payment gateway is no longer accessible from a patched server. The gateway has the URL https://ics2ws.ic3.com/commerce/1.x/transactionProcessor. Before the pat

[FD] Enghouse Interactive´s CCSP 7.2.5 API XXE and SSRF,vulnerability via unauthenticated GET Request

2019-05-10 Thread David H