New Bugs Found in OpenSSL, Software That Caused 'Heartbleed'

Advertisement
By Reuters | Updated: 6 June 2014 09:14 IST
Security researchers have uncovered new bugs in the Web encryption software that caused the pernicious "Heartbleed" Internet threat that surfaced in April.

Experts said the newly discovered vulnerabilities in OpenSSL, which could allow hackers to spy on communications, do not appear to be as serious a threat as "Heartbleed."

The new bugs were disclosed on Thursday as the group responsible for developing that software released an OpenSSL update that contains seven security fixes.

Experts said that websites and technology firms that use OpenSSL technology should install the update on their systems as quickly as possible. Still, they said that could take several days or weeks because companies need to first test systems to make sure they are compatible with the update.

Advertisement

"They are going to have to patch. This will take some time," said Lee Weiner, senior vice president with cyber-security software maker Rapid7.

Advertisement

OpenSSL technology is used on about two-thirds of all websites, including ones run by Amazon.com Inc, Facebook Inc, Google Inc and Yahoo Inc. It is also incorporated into thousands of technology products from companies, including Cisco Systems Inc, Hewlett-Packard Co, IBM, Intel Corp and Oracle Corp.

(Also see: Google, Facebook, other tech firms pledge millions to prevent another Heartbleed)

The widespread "Heartbleed" bug surfaced in April when it was disclosed that the flaw potentially exposed users of those websites and technologies to attack by hackers who could steal large quantities of data without leaving a trace. That prompted fear that attackers may have compromised large numbers of networks without their knowledge.

Advertisement

Security experts said on Thursday that the newly discovered bugs are more difficult to exploit than "Heartbleed," making those vulnerabilities less of a threat.

(Also see: Heartbleed spooks 39 percent of Web surfers: Survey)

Still, until users of the technology update their systems, "there is a window of opportunity" for sophisticated hackers to launch attacks and exploit the newly uncovered vulnerabilities, said Tal Klein, vice president of strategy with cloud security firm Adallom.

Advertisement

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y19s 5G Launched in India With 6,000mAh Battery: See Price
  2. OnePlus 15 to Get New OP Gaming Core Tech for Smoother Gameplay
  3. Samsung Galaxy S26 Series Could Launch on This Date
  4. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date Revealed
  5. Apple's iOS 26.1 May Launch on This Date, Followed By iOS 26.2 Beta Rollout
  6. Lenovo AI Glasses V1 Debuts With Real-Time Translation, Micro LED Displays
  1. India Is Shaping a Global Framework for Ethical and Human-Centric AI: PM Modi
  2. Sotta Sotta Nanaiyuthu Streaming Now on OTT: Know Where to Watch This Tamil Comedy Drama Movie Online
  3. Robin Hood Season 1 Now Streaming on Prime Video: Everything You Need to Know
  4. Bitcoin Price Drops Below $107,500 Amidst Weakening Spot Demand, Macro Uncertainty
  5. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date, Design Revealed
  6. Vivo Y19s 5G Launched in India With 6,000mAh Battery, Dimensity 6300 SoC: Price, Specifications
  7. ChatGPT Atlas, Perplexity’s Comet and Other AI Browsers Can Bypass Paywalls: Report
  8. Silent Hill 2 Remake's Xbox Series S/X Version Listed on ESRB Website, Suggesting Upcoming Launch
  9. Vivo S50, Vivo S50 Pro Mini Reportedly Clear Radio Certification Before Launch in China
  10. Apple’s Product Launch Timeline for 2026 Leaked; New iPad Mini, MacBook Air and AI-Powered Siri Expected
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.