Heartbleed fix finds more security bugs in server code

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
More security holes have been uncovered in the same software that was found to harbour the dangerous "Heartbleed" bug.

Heartbleed was found in security software used on many websites to ensure data was not spied upon as it passed back and forth.

About 500,000 websites were believed to be vulnerable to attacks that exploited the Heartbleed vulnerability.

The newly discovered bugs are not thought to be as serious as Heartbleed and are harder to exploit.

The software package harbouring all the vulnerabilities is known as OpenSSL and is used to scramble, or encrypt, data as it is swapped between users and a site.

Tech companies including Google, Facebook, Yahoo and Amazon and many others all use OpenSSL.

The fresh batch of vulnerabilities was found as a result of work done to close Heartbleed and ensure other parts of the software were secure. The discovery of Heartbleed led to many big firms pledging cash to the small organisation that developed OpenSSL to help it improve its bug finding and fixing efforts.

Updated versions of OpenSSL that have the bugs patched are now available and anyone running vulnerable versions are being urged to update as soon as possible.

"They are going to have to patch. This will take some time," Lee Weiner, a spokesman for security firm Rapid7 told Reuters.

If exploited the bugs would let attackers run their own programs on a target server or stop it working. The most serious bug would let an attacker interpose themselves between a victim and the server they were using and spy on the data as it passed back and forth.

Read more: http://www.bbc.com/news/technology-27732266
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top