businesspress24.com - Clavister and Heartbleed
 

Clavister and Heartbleed

ID: 1296459

Clavister solutions not affected - here's what you need to know

(PresseBox) - You will have heard about the 'Heartbleed' vulnerability (CVE-2014-0160) which was revealed earlier this week.
Heartbleed affects the OpenSSL security system used to protect many global websites, potentially enabling an attacker to steal website encryption keys. Possessing these keys allows attackers to impersonate website administrators, and steal both current and previous traffic passing through the site.
Using the keys, attackers can capture user passwords, financial details, emails and secret documents. The vulnerability existed for two years before being discovered.
Heartbleed is believed to be the most serious vulnerability in SSL security systems to be uncovered, and it poses an immediate risk to companies using affected versions of OpenSSL on their websites, and consumers that have used those websites. Below are a series of actions to help businesses and consumers establish if this vulnerability affects them.
Clavister's products are not affected by this vulnerability, as we do not use OpenSSL for handling any type of SSL traffic.
For businesses:
ƒƒ- Any business using OpenSSL 1.0.1 through to 1.0.1f should update to the latest fixed version of the software (1.0.1g), or recompile OpenSSL without the affected 'heartbeat' extension.
ƒƒ- After moving to an unaffected version of OpenSSL, it's possible that your web server certificates may have been compromised or stolen as a result of exploitation. Contact the certificate authority for a replacement certificate.
ƒƒ- Businesses should also consider resetting end-user passwords that may have been visible in a compromised server's memory.
For consumers:
ƒƒ- This Mashable article gives a useful guide to which popular websites and services may have been affected, and gives the website's recommended advice on whether you need to change your password.




ƒƒ- Avoid potential phishing emails from attackers asking you to update your password - and avoid clicking on links in emails asking you to change passwords. Only visit the official website to change passwords.


Themen in dieser Pressemitteilung:


Unternehmensinformation / Kurzprofil:



Leseranfragen:



PresseKontakt / Agentur:



drucken  als PDF  an Freund senden  Advantech&Intel to Launch IoT Gateway Solutions
Lantech IES-3307C
Bereitgestellt von Benutzer: PresseBox
Datum: 11.04.2014 - 04:55 Uhr
Sprache: Deutsch
News-ID 1296459
Anzahl Zeichen: 0

contact information:
Contact person:
Town:

Schorndorf


Phone:

Kategorie:

Hazadous Materials Management


Anmerkungen:


Diese Pressemitteilung wurde bisher 131 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"Clavister and Heartbleed
"
steht unter der journalistisch-redaktionellen Verantwortung von

sysob IT-Distribution GmbH&Co. KG (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).


Alle Meldungen von sysob IT-Distribution GmbH&Co. KG



 

Who is online

All members: 10 565
Register today: 0
Register yesterday: 0
Members online: 0
Guests online: 64


Don't have an account yet? You can create one. As registered user you have some advantages like theme manager, comments configuration and post comments with your name.