HTTPS FREAK vulnerability

Post Reply
User avatar
mark
Site Admin
Posts: 5514
Joined: Tue Apr 25, 2000 6:56 pm

HTTPS FREAK vulnerability

Post by mark »

There is a security vulnerability in OpenSSL with the name "FREAK" that can affect Thunderstone Search Appliances as well as any browser or server using SSL protocols. See CVE-2015-0204 and https://freakattack.com .

Turning off low security and export grade ciphers will eliminate the vulnerability. On your Thunderstone Search appliance admin interface go to "HTTPS/SSL Ciphers" under "System Wide Settings". If you have "DEFAULT" or "DEFAULT:!LOW" change it to "DEFAULT:!LOW:!EXPORT" then Update.
Post Reply