sincity Posted June 6, 2014 Share Posted June 6, 2014 http://cdn.mos.techradar.com/art/internet/heartbleed_padlock-470-75.jpgGood news for those who fear being victims of any OpenSSL vulnerability. Since the discovery of the Heartbleed bug, security experts are pouring over its source code, in a bid to tidy up what could be described as a messy coding chaos.And the first patches have followed swiftly. The OpenSSL open source project has issued a security patch that aims to fix 7 vulnerabilities, 2 of which have been deemed critical by the SAMS Internet Storm Center.The first one is a so-called man-in-the-middle flaw, using a OpenSSL exploit to tamper with traffic between clients and servers. Everything you need to know about HeartbleedIt was discovered by Japanese researcher Masashi Kikuchi from security company Lepidum and has been around for over 16 years, since the very inception of OpenSSL.Kikuchi blames the insufficient number of code reviews as well as the lack of experience of reviewers for the time it took to unearth this vulnerability.Another critical flaw was identified six weeks ago and is classified as a "Datagram Transport Layer Security (DTLS) invalid fragment vulnerability", which is a buffer overrun attack, allowing an arbitrary code to be executed on the compromised host.http://rss.feedsportal.com/c/669/f/415085/s/3b3b217b/sc/15/mf.gifhttp://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/1/rc.imghttp://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/2/rc.imghttp://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/rc/3/rc.imghttp://da.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/a2.imghttp://pi.feedsportal.com/r/199108139170/u/49/f/415085/c/669/s/3b3b217b/sc/15/a2t.imghttp://feeds.feedburner.com/~r/techradar/software-news/~4/VkJP9TQ0SKk Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.