New Bugs Discovered in OpenSSL Encryption

Advertisement
By Reuters | Updated: 20 March 2015 10:20 IST
New bugs in the widely used encryption software known as OpenSSL were disclosed on Thursday, though experts say do not pose a serious threat like the "Heartbleed" vulnerability in the same technology that surfaced a year ago.

"Heartbleed" triggered panic throughout the computer industry when it was reported in April 2014. That bug forced dozens of computers, software and networking equipment makers to issue patches for hundreds of products, and their customers had to scour data centers to identify vulnerable equipment.

Cyber-security watchers had feared the new round of bugs would be as serious as "Heartbleed," according to experts who help companies identify vulnerabilities in their networks. The concerns surfaced after the OpenSSL Project, which distributes OpenSSL software, warned several days ago that it planned to release a batch of security patches.

Advertisement

"You need to take all vulnerabilities seriously, but I'm kind of disappointed. There's been a week building up to this," said Cris Thomas, a strategist with cyber-security firm Tenable Network Security Inc.

The OpenSSL project released updates for four versions of the software, covering 12 security fixes for vulnerabilities reported to them in recent months by several cyber-security researchers. The threats include one that makes affected systems vulnerable to so-called denial-of-service attacks that disrupt Web traffic, though none threaten the "crypto" technology used to encrypt data, Ristic said.

Advertisement

Ivan Ristic, director of application security with Qualys Inc, said he was not too concerned about the new bugs because most involved programming errors in a new version of OpenSSL, which is not widely used.

"It doesn't seem a big story," Ristic said. "I think people feared it would be bad, which is where all the hype came from."

Advertisement

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Z Fold 8 Ultra Listed on BIS Database, May Launch Soon
  1. James Webb Space Telescope Weighs Most Distant Dormant Black Hole Ever Detected
  2. Stellar Blade: Blood Rain Protagonist Will Have More of a Personality, Says Shift Up
  3. Samsung Galaxy Tab Active 6 Reportedly Set to Launch in 2027 With 5G Connectivity
  4. iOS 27 Finally Adds Separate Volume Controls for Ringtones and Alarms, Just Like Android Phones
  5. UK Regulator Proposes Allowing Retail Funds to Hold Up to 10 Percent in Crypto ETNs
  6. Samsung Galaxy Z Fold 8 Ultra Reportedly Listed on BIS Database, Tipster Leaks Key Specifications
  7. Redmi Note 17 Visits EEC Certification Database Along With a New Vivo Handset, Hinting at Imminent Global Launch
  8. OnePlus 15 Gains AirDrop Support via Quick Share as Google Expands Availability Beyond Pixel, Samsung Phones
  9. Apple Will Soon Allow Android, Windows Users to Share Photos to iCloud Shared Albums
  10. WhatsApp Claims NSO Group-Linked Entity Unsuccessfully Carried Out Fresh Phishing Attacks Against Users
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.