New OpenSSL bugs dodge the Heartbleed bullet

Heartbleed
Heartbleed

OpenSSL's frantic move to fix certain vulnerabilities in the protocol wasn't to prevent the next Heartbleed despite the fact that it labelled two problems as "high severity".

The project team behind OpenSSL released the update on Thursday. It brings with it patches for 14 different bugs, including two that are most worrying with the labels CVE-2015-0291 and CVE-2015-0204.

The CVE-2014-0204 is commonly known as the FREAK vulnerability whereas the other one (CVE-2015-0291) could conceivably be used the carry out a denial of service attack, according to OpenSSL.

Stanford University student David Ramos discovered the bugs on February 26 and Ken Westin, senior security analyst at Tripwire, thinks the security community "dodged a bullet" in relation to the new vulnerabilities being a new Heartbleed.

Upgrade now!

Heartbleed was first discovered a little over a year after lying undiscovered for over two years. That vulnerability allowed attackers to read up to 64KB of the host's memory before repeating it to read more RAM.

Now it seems the security boffins are on high alert. When the bugs were first outed by OpenSSL just last week, the doom-mongers were already looking to it as a new Heartbleed thanks to OpenSSL's decision to tag it as "high severity".

As for the other 12 bugs, all of them are rated as "moderate" or "low". Even so, OpenSSL is advising anyone still running the older versions of the protocol (1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf) to upgrade to newer versions immediately.

Latest in Pro
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
Context Windows
Why are AI context windows important?
BERT
What is BERT, and why should we care?
A person holding out their hand with a digital AI symbol.
AI is booming — but are businesses seeing real impact?
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
Latest in News
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
iPhone 13 mini
The iPhone mini won't be returning, according to rumors – and you think that's a mistake