Heartbleed: OpenSSL Vulnerability Puts Servers At Risk

Wednesday, April 09, 2014

A new vulnerability in the OpenSSL cryptographic software library was revealed yesterday. It has quickly gathered worldwide attention as an extremely serious problem as it can allow remote access to critical information on servers.

The vulnerability - nicknamed "Heartbleed" - can allow anyone on the Internet to directly access the memory of systems that are using the vulnerable version of the OpenSSL library.

Heartbleed has been assigned CVE-2014-0160. We encourage our customers to check their VPSs to ensure that their OpenSSL has been updated.

Some good references on the subject include:

- http://heartbleed.com/ - a great summary of the issue, including background, details of affected versions, and more information about is exposed.

- Attack of the week: OpenSSL Heartbleed - a more technical overview of the issue, including analysis of the vulnerable code, as well as some testing tools to check if your server is vulnerable.

CVE-2014-0160


Post a comment

Preload Preload Preload