Options

CVE-2014-0160 ( HeartBleed bug)

chaser7783chaser7783 Member Posts: 154
There was a new vulnerability posted recently pertaining to OpenSSL. The attack will allow a remote attacker to read up to 64kBytes of system memory from your system per attack attempt. The attack works against servers as well as against clients. Sadly yahoo.com and even Eff.org are vulnerable.

Here is a site to test if a web server is vulnerable: Test your server for Heartbleed (CVE-2014-0160)
Sample list of vulnerable sites: Heartbleed Exposure Alexa Top 1000 - Pastebin.com

Information on vulnerability: Heartbleed Bug
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
Fix: https://www.openssl.org/news/secadv_20140407.txt

Comments

Sign In or Register to comment.