OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic

Advertisement
By NDTV Correspondent | Updated: 8 April 2014 15:48 IST
A serious flaw in the implementation of OpenSSL, a fundamental security measure used by millions of websites, could expose sensitive information to attackers, including private messages, login credentials and credit card details. The vulnerability, officially tagged CVE-2014-0160 but also known as "Heartbleed", potentially allows attackers to retrieve entire OpenSSL decryption keys from an affected server, allowing them to decrypt secure communications without leaving any sign of brute-force intrusion.

In addition to stealing names, passwords, and message contents, attackers could also disguise themselves as legitimate users, thus eavesdropping and stealing all data flowing in and out of a vulnerable service.

The flaw is not in the encryption method itself, but rather in the way the OpenSSL implementation manages memory. If an attacker sends a deliberately malformed request to the server, it automatically responds with up to 64kB of data that might contain sensitive information.

The problem was known internally and a fix was being prepared, but security firm CloudFlare published information about it before the fix was ready for general release, in an attempt to promote a fix for their own OpenSSL implementation. Web administrators who rely on OpenSSL might not have time to apply the fix before attackers decide to put the flaw into practice.

OpenSSL versions 1.01 and 1.02 beta are affected. Administrators running 1.01f or earlier are advised to upgrade to 1.01g. A 1.02 beta 2 release will fix the vulnerability in the beta channel, when it is released. Security firm Codeomnicon estimates that at least 66 percent of active sites on the Internet could be affected, in addition to a massive number of email, instant message, virtual private network and various other services.

There is no known evidence of a successful attack on any person or organisation due to the Heartbleed vulnerability.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus N6x Design, Colour Options Teased Ahead of India Launch
  2. Boat Airdopes ProClip Review: Built for Everyday Use
  3. Tecno Camon 50 Ultra 5G Sale Begins in India Today
  4. Samsung Galaxy A55, Galaxy A35 One UI 9 Internal Testing Begins, Leak Suggests
  5. One UI 9 Beta Improves Samsung Galaxy S26 Ultra's Privacy Display Feature
  6. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  7. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  1. Offline UPI Payments With NFC Support Could Launch in India Soon
  2. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  3. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  4. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  5. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  6. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  7. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  8. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  9. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  10. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.