Hackers Claim to Have Found New OpenSSL Flaw Similar to Heartbleed

  • 28 April 2014
  • 2 replies
  • 512 views

Userlevel 7
Badge +54
A group of hackers claims to have identified a new vulnerability in the latest version of OpenSSL. They say they’ve found a security hole that’s similar to the now infamous Heartbleed bug in OpenSSL 1.0.1g, but experts are questioning their claims. 

“We have just found an vulnerability in the patched version OpenSSL. A missing bounds check in the handling of the variable DOPENSSL_NO_HEARTBEATS. We could successfully Overflow the DOPENSSL_NO_HEARTBEATS and retrieve 64kb chunks of data again on the updated version,” the hackers wrote on Pastebin.
 
Full Article
 
However, I think we will have to wait for the final verdict on this one:
 
 
Hacker claims about bug in fixed OpenSSL likely a scam

Security experts have expressed doubts about a hacker claim that there is a new vulnerability in the patched version of OpenSSL, the widely used cryptographic library repaired in early April.

A group of five hackers writes in a posting on Pastebin that they worked for two weeks to find the bug and developed code to exploit it. They have offered the code for the price of 2.5 bitcoins, around $870 (€627).

A new flaw in OpenSSL could pose just as much of a threat as Heartbleed did. But the hackers’ claim was met with immediate suspicion on Full Disclosure, a forum for discussing vulnerability reports.

One commentator, Todd Bennett, wrote the technical description of their claim is “rather extraordinary.”
 
Full Article
 

 


2 replies

Userlevel 7
Badge +56
If this turns out to be real it's really going to call SSL into question.
Userlevel 7
Badge +54
It will do if it is genuine. The problem is that people are trying to jump on the Heartbleed bandwagon because it is all free publicity amongst their peers.

Reply