OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic

Advertisement
By NDTV Correspondent | Updated: 8 April 2014 15:48 IST
A serious flaw in the implementation of OpenSSL, a fundamental security measure used by millions of websites, could expose sensitive information to attackers, including private messages, login credentials and credit card details. The vulnerability, officially tagged CVE-2014-0160 but also known as "Heartbleed", potentially allows attackers to retrieve entire OpenSSL decryption keys from an affected server, allowing them to decrypt secure communications without leaving any sign of brute-force intrusion.

In addition to stealing names, passwords, and message contents, attackers could also disguise themselves as legitimate users, thus eavesdropping and stealing all data flowing in and out of a vulnerable service.

The flaw is not in the encryption method itself, but rather in the way the OpenSSL implementation manages memory. If an attacker sends a deliberately malformed request to the server, it automatically responds with up to 64kB of data that might contain sensitive information.

The problem was known internally and a fix was being prepared, but security firm CloudFlare published information about it before the fix was ready for general release, in an attempt to promote a fix for their own OpenSSL implementation. Web administrators who rely on OpenSSL might not have time to apply the fix before attackers decide to put the flaw into practice.

OpenSSL versions 1.01 and 1.02 beta are affected. Administrators running 1.01f or earlier are advised to upgrade to 1.01g. A 1.02 beta 2 release will fix the vulnerability in the beta channel, when it is released. Security firm Codeomnicon estimates that at least 66 percent of active sites on the Internet could be affected, in addition to a massive number of email, instant message, virtual private network and various other services.

There is no known evidence of a successful attack on any person or organisation due to the Heartbleed vulnerability.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Pad 5e Launched Alongside iQOO Watch GT 2 and iQOO TWS 5
  2. DeepSeek-OCR Could Change How AI Reads Text From Images
  3. WhatsApp Says AI Firms Can't Offer Chatbot Access via WhatsApp Business
  4. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  5. Sony WH-1000XM6 Review: The Best Just Got Better
  6. Poco F8 Ultra Listing on NBTC Certification Site Hints at Imminent Launch
  7. OpenAI's AI-Powered Web Browser Is Here: Know What It Can Do
  8. BSNL Samman Plan For Senior Citizens Announced at This Price
  1. Samsung Galaxy XR Headset Launching Today: Know Price, Features, and Specifications
  2. Smartwatch Breakthrough Brings GPS Accuracy Down to a Few Centimetres
  3. SpaceX Launches 10,000th Starlink Satellite, Sets New Annual Record
  4. Scientists Discover New Seismic Clue to Predict Mount Etna Eruptions
  5. NASA and ESA Trace Mysterious Lunar Flashes to Meteors and Gas Leaks
  6. Valsala Club Is Streaming Now: Know All About the Malayali Comedy-Drama Movie
  7. Ganoshotru OTT Release: Know When and Where to Watch the Bengali Crime-Thriller Online
  8. Mr Shudai OTT Release: Know When and Where to Watch the Punjabi Horror-Comedy
  9. SpaceX May Miss First Crewed Moon Landing as NASA Reopens Artemis Bid
  10. OpenAI Introduces ChatGPT Atlas, an AI-Powered Web Browser With Agentic Capabilities
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.