Showing posts with label Heart Bleed. Show all posts
Showing posts with label Heart Bleed. Show all posts

Wednesday, 8 July 2015

Announces Update For OpenSSL Vulnerability



The OpenSSL developers have updated announced that will fix a vulnerability in versions 1.0.2d and 1.0.1p software. Versions 1.0.0 or 0.9.8 are not vulnerable. The leak is classified as "high", which is the highest level for vulnerabilities that uses OpenSSL.

This relates to vulnerabilities allowing attackers to cause a denial of service, a large amount of server memory may leak or an attacker could execute arbitrary code remotely. What exactly will the announced update remedy has not been disclosed.OpenSSL is one of the most widely used software for encrypting Internet connections, for example between websites and their visitors. Last April the Heart Bleed very serious bug was discovered in OpenSSL, allowing attackers memory information from Web servers to steal, such as passwords. The update is available from Thursday, July 9th.

Saturday, 12 April 2014

NSA for 2 years at the height of Heart Bleed

According to the U.S. News Agency Bloomberg NSA was familiar with the Heart Bleed bug for 2 years and she has the vulnerability in OpenSSL frequently used to gather information. Bloomberg cites sources that are "aware of the situation" are.
The decision of the NSA to keep the secret bug in the framework of national security interests, the debate about the role of computer experts from the U.S. government, revived considerably. Again
Heart Bleed seems one of the biggest leak in the history of the Internet to have. As many as two-thirds of the world's websites is touched. The discovery and the advisory that five days ago was published by researchers has led to massive consumers have changed their passwords, the Canadian government has postponed the electronic tax return and that large technology companies such as Cisco Systems and Juniper Networks patches for their systems released. There are also a lot of new SSL certificates issued.
The Heart Bleed bug quietly adding to the arsenal, the NSA has been able to obtain. Passwords and other important information The price for this was high. Millions of ordinary users are left to their own and all that time was vulnerable to attack by secret services and cyber criminals.
Jason Healey, director of the "cyber statecraft initiative at the Atlantic Council" and a former Air Force officer explains: "The security community will not chip them really leave after this revelation."
The NSA has just been denied before the vulnerability became public last week. Bleed Heart of informed on twitter