Тема: [News] Вразливості, баґи, косяки та інше..
RedHat привітала з першим днем весни новиною про значний косяк в SSL.. здається постраждали всі реалізації крім nss.. якщо вірити wikipedia його юзають:
AOL, Red Hat, Sun Microsystems/Oracle Corporation, Google and other companies and individual contributors have co-developed NSS. Mozilla provides the source code repository, bug tracking system, and infrastructure for mailing lists and discussion groups. They and others named below use NSS in a variety of products, including the following:
Mozilla client products, including Firefox, Thunderbird, SeaMonkey, and Firefox for mobile (Fennec).[6]
AOL Communicator and AOL Instant Messenger (AIM)
Google Chrome and Chromium except for Android / OS X,[7] [8] and Opera
Open source client applications such as Evolution, Pidgin, OpenOffice.org 2.0 and later, and Apache OpenOffice.
Server products from Red Hat: Red Hat Directory Server, Red Hat Certificate System, and the mod nss SSL module for the Apache web server.
Sun server products from the Sun Java Enterprise System, including Sun Java System Web Server, Sun Java System Directory Server, Sun Java System Portal Server, Sun Java System Messaging Server, and Sun Java System Application Server, open source version of Directory Server OpenDS.
Libreswan IKE/IPsec requires NSS. It is a fork of Openswan which could optionally use NSS.
Тож як у вас справи із безпекою?