OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic

Advertisement
By NDTV Correspondent | Updated: 8 April 2014 15:48 IST
A serious flaw in the implementation of OpenSSL, a fundamental security measure used by millions of websites, could expose sensitive information to attackers, including private messages, login credentials and credit card details. The vulnerability, officially tagged CVE-2014-0160 but also known as "Heartbleed", potentially allows attackers to retrieve entire OpenSSL decryption keys from an affected server, allowing them to decrypt secure communications without leaving any sign of brute-force intrusion.

In addition to stealing names, passwords, and message contents, attackers could also disguise themselves as legitimate users, thus eavesdropping and stealing all data flowing in and out of a vulnerable service.

The flaw is not in the encryption method itself, but rather in the way the OpenSSL implementation manages memory. If an attacker sends a deliberately malformed request to the server, it automatically responds with up to 64kB of data that might contain sensitive information.

The problem was known internally and a fix was being prepared, but security firm CloudFlare published information about it before the fix was ready for general release, in an attempt to promote a fix for their own OpenSSL implementation. Web administrators who rely on OpenSSL might not have time to apply the fix before attackers decide to put the flaw into practice.

OpenSSL versions 1.01 and 1.02 beta are affected. Administrators running 1.01f or earlier are advised to upgrade to 1.01g. A 1.02 beta 2 release will fix the vulnerability in the beta channel, when it is released. Security firm Codeomnicon estimates that at least 66 percent of active sites on the Internet could be affected, in addition to a massive number of email, instant message, virtual private network and various other services.

There is no known evidence of a successful attack on any person or organisation due to the Heartbleed vulnerability.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Ultra With 200-Megapixel Rear Camera Launched at This Price
  2. Oppo Pad Air 5 With a 10,050mAh Battery Launched at This Price
  3. Dracula: A Love Tale Now Available For Streaming Online
  4. Failing Starlink Satellite Photographed in Orbit Before Fiery Reentry
  1. Xiaomi 17 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, Leica-Tuned 200-Megapixel Camera: Price, Features
  2. Astrophysicists Map Invisible Universe Using Warped Galaxies to Reveal Dark Matter
  3. Why Venus Is the Brightest Morning Star Visible From Earth
  4. Oppo Pad Air 5 Launched With 10,050mAh Battery, 12.1-Inch Display: Price, Specifications
  5. Dracula: A Love Tale Now Available For Streaming Online: What You Need to About its Plot, Cast, and More
  6. Xiaomi 17 Ultra Launching Today: Know Price, Features, Specifications and More
  7. South Korean Startup Innospace Fails on First Orbital Launch Attempt of Hanbit-Nano Rocket
  8. Failing Starlink Satellite Photographed in Orbit Before Fiery Reentry
  9. Russia Patents Rotating Space Station Concept to Generate Artificial Gravity in Orbit
  10. Interstellar Comet 3I/ATLAS Shows Wobbling Jets in Rare Sun-Facing Tail, Surprising Astronomers
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.