Release date:
Updated on:
Affected Systems:
OpenSSL Project OpenSSL 1.0.2-beta
OpenSSL Project OpenSSL 1.0.1
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0160
OpenSSL is an open-source SSL implementation that implements high-strength encryption for network communication. It is widely used in various network applications.
The border check is missing in the TLS heartbeat extension, which may cause 64 KB of Memory leakage to the connected client or server. Only 1.0.1 and 1.0.2-beta versions of OpenSSL are affected, including 1.0.1f and 1.0.2-beta1.
<* Source: Neel Mehta
Link: https://www.openssl.org/news/secadv_20140407.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenSSL Project
---------------
The OpenSSL Project has released a Security Bulletin (secadv_20140407) and corresponding patches:
Secadv_20140407: TLS heartbeat read overwriting (CVE-2014-0160)
Link: https://www.openssl.org/news/secadv_20140407.txt
OpenSSL details: click here
OpenSSL: click here
Recommended reading:
Provides FTP + SSL/TLS authentication through OpenSSL and implements secure data transmission.