RSS Feed
News
Oct
16
POODLE -SSLv3 Vulnerability
Posted by Anthony N on 16 October 2014 05:23 PM

POODLE stands for Padding Oracle On Downgraded Legacy Encryption. This vulnerability allows a man-in-the-middle attacker to decrypt ciphertext using a padding oracle side-channel attack.

Please read more about this at the following URLs.

https://access.redhat.com/node/1232123

http://www.percona.com/blog/2014/10/15/how-to-close-poodle-sslv3-security-flaw-cve-2014-3566/

 

We have deployed configuration changes to all servers which has ntServerGuard installed to disable SSLv3. Servers without ntServerGaurd are being patched manually.

If you find your server still has this vulnerability, please feel free to contact our support team ASAP.

 

UPDATE

* Patched OpenSSL package is relased already. For cPanel servers, package will be updated along with UPCP. We have pushed the update via ntSG already. 


Comments (0)
Post a new comment
 
 
Full Name:
Email:
Comments: