New Bugs Discovered in OpenSSL Encryption

Advertisement
By Reuters | Updated: 20 March 2015 10:20 IST
New bugs in the widely used encryption software known as OpenSSL were disclosed on Thursday, though experts say do not pose a serious threat like the "Heartbleed" vulnerability in the same technology that surfaced a year ago.

"Heartbleed" triggered panic throughout the computer industry when it was reported in April 2014. That bug forced dozens of computers, software and networking equipment makers to issue patches for hundreds of products, and their customers had to scour data centers to identify vulnerable equipment.

Cyber-security watchers had feared the new round of bugs would be as serious as "Heartbleed," according to experts who help companies identify vulnerabilities in their networks. The concerns surfaced after the OpenSSL Project, which distributes OpenSSL software, warned several days ago that it planned to release a batch of security patches.

"You need to take all vulnerabilities seriously, but I'm kind of disappointed. There's been a week building up to this," said Cris Thomas, a strategist with cyber-security firm Tenable Network Security Inc.

Advertisement

The OpenSSL project released updates for four versions of the software, covering 12 security fixes for vulnerabilities reported to them in recent months by several cyber-security researchers. The threats include one that makes affected systems vulnerable to so-called denial-of-service attacks that disrupt Web traffic, though none threaten the "crypto" technology used to encrypt data, Ristic said.

Ivan Ristic, director of application security with Qualys Inc, said he was not too concerned about the new bugs because most involved programming errors in a new version of OpenSSL, which is not widely used.

"It doesn't seem a big story," Ristic said. "I think people feared it would be bad, which is where all the hype came from."

Advertisement

© Thomson Reuters 2015

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. YouTube Takes on OpenAI's Sora With AI-Generated Shorts Feature
  2. Dhurandhar OTT Release Date Update: When and Where to Watch it Online?
  3. Ubisoft Cancels Prince of Persia: Sands of Time Remake, Delays 7 Games
  4. Realme Neo 8 Launched With 8,000mAh Battery: See Price, Features
  5. Aadukalam Streaming on SunNXT: Know Everything About Plot, Cast, and More
  6. Top Last Minute Deals on Smartphones, Smart TVs and Home Appliances
  7. Here's When the Redmi Note 15 Pro and Note 15 Pro+ Will Launch in India
  8. OnePlus 15T Spotted on Certification Site, Charging Details Revealed
  9. OnePlus Nord 6 Arrives on Geekbench With These Key Specifications
  10. Crimson Desert Has Officially Gone Gold, Pearl Abyss Confirms
  1. Realme Neo 8 Launched With Snapdragon 8 Gen 5 Chip, 8,000mAh Battery: Price, Features
  2. Apple Asks Delhi High Court to Stop Competition Commission of India From Seeking Its Financials
  3. Amazon Great Republic Day Sale: Top Last Minute Deals on Smartphones, Smart TVs and Home Appliances
  4. Amazon Great Republic Day Sale: Best Deals on Robot Vacuum Cleaners
  5. OnePlus 15T Lands on 3C Certification Database Ahead of Launch in China: Expected Specifications
  6. Crimson Desert Has Officially Gone Gold, Launch Set for March 19
  7. Acer Chromebook Spin 311, Chromebook 311 Launched With MediaTek Kompanio 540 CPU: Price, Features
  8. Samsung Galaxy S26+ Bags 3C Certification; Might Not Launch With Charging Upgrade
  9. Apple Could Turn Siri Into an AI Chatbot to Rival OpenAI, Google: Report
  10. Powerful X-Class Solar Flare Sends CME Toward Earth, Storms Possible
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.