New Bugs Found in OpenSSL, Software That Caused 'Heartbleed'

Advertisement
By Reuters | Updated: 6 June 2014 09:14 IST
Security researchers have uncovered new bugs in the Web encryption software that caused the pernicious "Heartbleed" Internet threat that surfaced in April.

Experts said the newly discovered vulnerabilities in OpenSSL, which could allow hackers to spy on communications, do not appear to be as serious a threat as "Heartbleed."

The new bugs were disclosed on Thursday as the group responsible for developing that software released an OpenSSL update that contains seven security fixes.

Experts said that websites and technology firms that use OpenSSL technology should install the update on their systems as quickly as possible. Still, they said that could take several days or weeks because companies need to first test systems to make sure they are compatible with the update.

Advertisement

"They are going to have to patch. This will take some time," said Lee Weiner, senior vice president with cyber-security software maker Rapid7.

Advertisement

OpenSSL technology is used on about two-thirds of all websites, including ones run by Amazon.com Inc, Facebook Inc, Google Inc and Yahoo Inc. It is also incorporated into thousands of technology products from companies, including Cisco Systems Inc, Hewlett-Packard Co, IBM, Intel Corp and Oracle Corp.

(Also see: Google, Facebook, other tech firms pledge millions to prevent another Heartbleed)

The widespread "Heartbleed" bug surfaced in April when it was disclosed that the flaw potentially exposed users of those websites and technologies to attack by hackers who could steal large quantities of data without leaving a trace. That prompted fear that attackers may have compromised large numbers of networks without their knowledge.

Advertisement

Security experts said on Thursday that the newly discovered bugs are more difficult to exploit than "Heartbleed," making those vulnerabilities less of a threat.

(Also see: Heartbleed spooks 39 percent of Web surfers: Survey)

Still, until users of the technology update their systems, "there is a window of opportunity" for sophisticated hackers to launch attacks and exploit the newly uncovered vulnerabilities, said Tal Klein, vice president of strategy with cloud security firm Adallom.

Advertisement

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  2. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  3. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  4. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  5. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  6. Xiaomi 17 Pro Series to Feature Rear Display, Snapdragon 8 Elite Gen 5 SoC
  7. Google: India Leads Nano Banana Trend; Shares Tip to Start Next One
  8. Check What's New for Your iPhone in Apple's Latest iOS 26 Update
  9. iOS 26 Released Alongside iPadOS 26, macOS Tahoe: Here's How to Download It
  10. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Leaked
  1. Vivo V60e 5G Design, Price in India Leaked; Said to Feature 6,500mAh Battery, Dimensity 7300 SoC
  2. Flipkart Big Billion Days Sale: Poco F7 5G Price to Drop Under Rs. 30,000, Discounts on Poco X7, M7 Series Revealed
  3. Bitcoin Holds Near $115,800 as Altcoins Face Selling Pressure
  4. GTA 6 Will Be the 'Largest Game Launch in History', Says Rockstar Games
  5. Google Says India Is Leading the Nano Banana Trend; Shares Tips on How You Can Start the Next One
  6. watchOS 26 Rolled Out With Workout Buddy, Hypertension Notifications and Liquid Glass Design
  7. Xiaomi 17 Pro Series Confirmed to Feature Rear Display, Snapdragon 8 Elite Gen 5 SoC
  8. Nothing Raises $200 Million in Series C Funding, Plans to Launch AI-Focused Devices
  9. Vivo X300 Global Variant Visits Geekbench With MediaTek Dimensity 9500 SoC
  10. Spotify Free Users in India Can Finally Search and Play Any Track, Design Playlist Covers, and More
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.