The OpenSSL Foundation has issued software updates to patch six new vulnerabilities, and two of them are critical. All versions of OpenSSL are vulnerable on client side. Only 1.0.1 and above are currently known to be vulnerable on server side. SSL VPN (virtual private network) products are believed to be especially vulnerable to this flaw. The vulnerabilities are not as critical as they are not subject to Heartbleed vulnerability. OpenSSL is urging companies to update their implementation as soon as possible as possible.
Source: https://thehackernews.com/2014/06/openssl-vulnerable-to-man-in-middle.html

