Message boards : BOINC client : Vulnerability in BOINC 6.4.5
Message board moderation
Author | Message |
---|---|
Send message Joined: 5 Feb 09 Posts: 3 ![]() |
Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5? BOINC "RSA_public_decrypt()" Spoofing Vulnerability |
Send message Joined: 5 Oct 06 Posts: 5142 ![]() |
Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5? The Secunia advisory references BOINC's own trac [trac]#823[/trac], where a fix has already been added to the code. (12 January 2009) So the developers are aware of the problem: full marks for that one. But the "recommended" download is dated 9 December 2008 (and I have re-downloaded it tonight - the executables are also datestamped 9 December 2008): no sign of a recall and re-issue. Not so good. |
![]() ![]() Send message Joined: 27 Jun 08 Posts: 641 ![]() |
Are developers aware of this published from Secunia vulnerability of BOINC 6.4.5? I have not been able to login on seti or seti beta for the last hour. I wonder if the account is locked out while they are fixing it? I can log in on other projects. Back up now. They must have been working on something. The main login page was displaying some debug info in the top left corner (i am guessing) as shown here: ![]() When I attempted to log in with the seti private key, the key was displayed in the top left instead of that email in the picture. |
Copyright © 2025 University of California.
Permission is granted to copy, distribute and/or modify this document
under the terms of the GNU Free Documentation License,
Version 1.2 or any later version published by the Free Software Foundation.