Vulnerability in BOINC 6.4.5

Message boards : BOINC client : Vulnerability in BOINC 6.4.5
Message board moderation

To post messages, you must log in.

AuthorMessage
Ivailo Bonev

Send message
Joined: 5 Feb 09
Posts: 3
Bulgaria
Message 22903 - Posted: 5 Feb 2009, 19:18:42 UTC

Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5?
BOINC "RSA_public_decrypt()" Spoofing Vulnerability
ID: 22903 · Report as offensive
Richard Haselgrove
Volunteer tester
Help desk expert

Send message
Joined: 5 Oct 06
Posts: 5082
United Kingdom
Message 22904 - Posted: 5 Feb 2009, 19:40:56 UTC - in response to Message 22903.  

Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5?
BOINC "RSA_public_decrypt()" Spoofing Vulnerability

The Secunia advisory references BOINC's own trac [trac]#823[/trac], where a fix has already been added to the code. (12 January 2009)

So the developers are aware of the problem: full marks for that one.

But the "recommended" download is dated 9 December 2008 (and I have re-downloaded it tonight - the executables are also datestamped 9 December 2008): no sign of a recall and re-issue. Not so good.
ID: 22904 · Report as offensive
Profile Joseph Stateson
Volunteer tester
Avatar

Send message
Joined: 27 Jun 08
Posts: 641
United States
Message 22908 - Posted: 5 Feb 2009, 21:55:02 UTC - in response to Message 22904.  
Last modified: 5 Feb 2009, 22:25:58 UTC

Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5?
BOINC "RSA_public_decrypt()" Spoofing Vulnerability

The Secunia advisory references BOINC's own trac [trac]#823[/trac], where a fix has already been added to the code. (12 January 2009)

So the developers are aware of the problem: full marks for that one.

But the "recommended" download is dated 9 December 2008 (and I have re-downloaded it tonight - the executables are also datestamped 9 December 2008): no sign of a recall and re-issue. Not so good.


I have not been able to login on seti or seti beta for the last hour. I wonder if the account is locked out while they are fixing it? I can log in on other projects.

Back up now. They must have been working on something. The main login page was displaying some debug info in the top left corner (i am guessing) as shown here:




When I attempted to log in with the seti private key, the key was displayed in the top left instead of that email in the picture.
ID: 22908 · Report as offensive

Message boards : BOINC client : Vulnerability in BOINC 6.4.5

Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.