Get a Pentest and security assessment of your IT network.

News

OpenSSL cert parsing bug causes infinite denial of service loop

OpenSSL has released a security update to address a vulnerability in the library that, if exploited, leads to denial of service conditions. Googles security researcher Tavis Ormandy discovered the certificate parsing vulnerability and reported his findings to the OpenSSL team on February 24, 2022. The vulnerability is tracked as CVE-2022-0778, and affects OpenSSL versions 1.0.2, 1.1.1n and 3.0. The fix is available for non-premium users, but only premium users will be offered a fix through 1.2zd. The most common scenario where exploitation of this flaw would be for a malicious client accessing a malicious server that serves up a problematic certificate.”]

Source: https://www.bleepingcomputer.com/news/security/openssl-cert-parsing-bug-causes-infinite-denial-of-service-loop/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Terrorism WEEKLY DIGESTTHREAT INTELLIGENCE FEED 23rd Jul 2nd

News

Attacker.NET : Server Management & Security, Website Malware Removal & Website Security