OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic

Advertisement
By NDTV Correspondent | Updated: 8 April 2014 15:48 IST
A serious flaw in the implementation of OpenSSL, a fundamental security measure used by millions of websites, could expose sensitive information to attackers, including private messages, login credentials and credit card details. The vulnerability, officially tagged CVE-2014-0160 but also known as "Heartbleed", potentially allows attackers to retrieve entire OpenSSL decryption keys from an affected server, allowing them to decrypt secure communications without leaving any sign of brute-force intrusion.

In addition to stealing names, passwords, and message contents, attackers could also disguise themselves as legitimate users, thus eavesdropping and stealing all data flowing in and out of a vulnerable service.

The flaw is not in the encryption method itself, but rather in the way the OpenSSL implementation manages memory. If an attacker sends a deliberately malformed request to the server, it automatically responds with up to 64kB of data that might contain sensitive information.

The problem was known internally and a fix was being prepared, but security firm CloudFlare published information about it before the fix was ready for general release, in an attempt to promote a fix for their own OpenSSL implementation. Web administrators who rely on OpenSSL might not have time to apply the fix before attackers decide to put the flaw into practice.

OpenSSL versions 1.01 and 1.02 beta are affected. Administrators running 1.01f or earlier are advised to upgrade to 1.01g. A 1.02 beta 2 release will fix the vulnerability in the beta channel, when it is released. Security firm Codeomnicon estimates that at least 66 percent of active sites on the Internet could be affected, in addition to a massive number of email, instant message, virtual private network and various other services.

There is no known evidence of a successful attack on any person or organisation due to the Heartbleed vulnerability.

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Epson EpiqVision Mini EF-22N Review: A Premium Portable Laser Projector
  2. MacBook Pro (2026) With M5 Pro, M5 Max Chips Launched in India: See Price
  3. MediaTek Showcases Emergency Satellite Alerts With Starlink, AI Glasses
  4. MacBook Air With M5 Chip, Up to 15.3-Inch Display Launched in India
  5. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Debut at MWC 2026
  1. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Unveiled at MWC 2026: Availability, Features
  2. Mike & Nick & Nick & Alice OTT Release Date: Know When and Where to Watch it Online
  3. MediaTek Showcases AI Glasses at MWC 2026; Demonstrates Emergency Satellite Alerts With Starlink
  4. Devagudi Now Streaming Online: Where to Watch Intense Drama Online?
  5. Jab Khuli Kitaab OTT Release Date: When and Where to Watch Pankaj Kapur and Dimple Kapadia Starrer Romantic Drama Online?
  6. Apple Introduces M5 Pro, M5 Max Chips With New Fusion Architecture on 2026 MacBook Pro Models
  7. Apple Studio Display, Studio Display XDR With 27-Inch 5K Displays Launched in India: Price, Features
  8. Jockey Now Available for Streaming Online: Where to Watch This Tamil Action Movie Online?
  9. NASA’s Carruthers Observatory Begins Mission to Study Earth’s Hydrogen Halo
  10. MacBook Pro (2026) Launched in India With M5 Pro, M5 Max Chips, Up to 16-Inch Display: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.