The OpenSSL Foundation has patched over a dozen vulnerabilities in its cryptographic code library, including a high severity bug that can be exploited for denial-of-service (DoS) attacks. The vulnerabilities exist in OpenSSL versions 1.0.1, 1.1.1. The team has also resolved a total of 12 low severity vulnerabilities in the latest versions of OpenSSL. OpenSSL Project will end support for OpenSSL on 31st December 2016, so users will not receive any security update from the beginning of 2017.
Source: https://thehackernews.com/2016/09/openssl-dos-attack.html

