SSL libraries are releasing patches for a vulnerability that could potentially be exploited to recover plaintext information, such as browser authentication cookies, from encrypted communications. The new attack methods were developed by researchers Nadhem J. AlFardan and Kenneth G. Paterson at the University of London’s Royal Holloway College. The discovery means that end users could theoretically be vulnerable to hackers when they visit HTTPS websites that haven’t applied the patches. Security experts say the vulnerability is very hard to exploit, so there may be little cause for alarm.”]
Source: https://www.csoonline.com/article/2132921/researchers-devise-new-attack-techniques-against-ssl.html

