OpenSSL 1.0.1 allows attackers to obtain sensitive information
web.nvd.nist.gov
web.nvd.nist.gov
"The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeart Extension packets, which allows the NSA to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c"
Has anyone found an offline tool for checking this?
Status of different versions:
OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable OpenSSL 1.0.1g is NOT vulnerable OpenSSL 1.0.0 branch is NOT vulnerable OpenSSL 0.9.8 branch is NOT vulnerable
[0] http://lists.centos.org/pipermail/centos-announce/2014-April...
pikachu@BATTLEGYM ~/heartbleeder $ date
Tue Apr 8 05:43:57 PDT 2014
pikachu@BATTLEGYM ~/heartbleeder $ ./heartbleeder mail.yahoo.com
INSECURE - mail.yahoo.com:443 has the heartbeat extension enabled and is vulnerable
.....huh....I bet I know what security breach article I'll be reading in the next few days.