Breaking News

Micron Announces New 2600 NVMe SSD HighPoint Launches Next-Gen External PCIe Gen5 x16 Switching Adapter LG Display Begins Mass Production of Ultimate Gaming OLED Panel with 4th-Generation OLED Technology PlayStation Plus Monthly Games for July 2025 Samsung Releases Smart Monitor M9 With AI-Powered QD-OLED Display

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

OpenSSL Cryptographic Bug Poses Threats User Data

OpenSSL Cryptographic Bug Poses Threats User Data

Enterprise & IT Apr 9,2014 0

A newly discovered bug in in the popular OpenSSL cryptographic software library has made data on many of the world's major websites vulnerable to theft by hackers. The so-called "Heartbleed Bug" allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).

The vulnerability could enable remote attackers to access sensitive data including passwords and secret keys that can decode traffic as it travels across the Internet.

The U.S. government's Department of Homeland Security has already advised businesses to review their servers to see if they were using vulnerable versions a type of OpenSSL. A fixed OpenSSL has been released and now it has to be deployed.

The bug was introduced to OpenSSL in December 2011 and has been out in the wild since OpenSSL release 1.0.1 on 14th of March 2012. OpenSSL 1.0.1g released on 7th of April 2014 fixes the bug.

Status of different versions of the OpenSSL:

- OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable
- OpenSSL 1.0.1g is NOT vulnerable
- OpenSSL 1.0.0 branch is NOT vulnerable
- OpenSSL 0.9.8 branch is NOT vulnerable

Security experts estimate that hundreds of thousands of web and email servers around the globe need to be patched as soon as possible to protect them from attack by hackers.

And according to a recent report from the Arstechnica.com web site, Security researcher Mark Loman was able to extract data from Yahoo Mail servers by using a free tool.

Tags:
Previous Post
HyperX Releases The FURY Memory Line For Overclockers
Next Post
New Asus ESC4000 G2S Series HPC GPU Servers For Intel Xeon Processors

Related Posts

Latest News

Micron Announces New 2600 NVMe SSD
Enterprise & IT

Micron Announces New 2600 NVMe SSD

HighPoint Launches Next-Gen External PCIe Gen5 x16 Switching Adapter
Enterprise & IT

HighPoint Launches Next-Gen External PCIe Gen5 x16 Switching Adapter

LG Display Begins Mass Production of Ultimate Gaming OLED Panel with 4th-Generation OLED Technology
Enterprise & IT

LG Display Begins Mass Production of Ultimate Gaming OLED Panel with 4th-Generation OLED Technology

PlayStation Plus Monthly Games for July 2025
Gaming

PlayStation Plus Monthly Games for July 2025

Samsung Releases Smart Monitor M9 With AI-Powered QD-OLED Display
Enterprise & IT

Samsung Releases Smart Monitor M9 With AI-Powered QD-OLED Display

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Noctua NH-D15 G2

Noctua NH-D15 G2

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed