Could a new OpenSSL defect be worse than Heartbleed?

Heartbleed
Heartbleed

OpenSSL is ready to rollout a major security update to patch a "high" severity security flaw that security researchers pray is not as bad as Heartbleed.

The project team behind OpenSSL explained that a new release will debut on March 19 that fixes security defects in versions 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf of OpenSSL, and Gavin Millard from Tenable Network Security is one of those keeping his fingers crossed.

"With the contributors to the OpenSSL project staying tight lipped apart from stating it will be classified as "High Severity", it would be prudent for organisations to identify all systems affected in advance of the patch to deploy the updates if required," said Millard, technical director at Tenable Network Security. "Hopefully this bug will be less severe than Heartbleed but, until Thursday, only a few will know."

Organisations that rely on OpenSSL will need to be quick to patch up the flaw. Being open source, the security update will allow malicious actors to work out how to take advantage of the vulnerability and attack any sites that haven't been updated.

What is Heartbleed?

Heartbleed was discovered last April after being undiscovered for two years and was a serious vulnerability in OpenSSL that allowed attackers to read up to 64KB of the host's memory before repeating it to read more RAM.

OpenSSL version 1.0.1g fixed the problem, but there were fears at the time that some sites simply wouldn't remember to update to the newest version. Even with the latest problem being patched up tomorrow, there will be concerns that some sites won't update.

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does