news.mlab.sh
Back to the feed
vulnerability

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

HighCVSS 8.2
Image: The Hacker News
Summary

The vulnerability affects various OpenSSL versions, including 3.0, 1.1.1, and 1.0.2. While exploitation hasn't been reported, CISA assigned a CVSS score of 8.2, and Ubuntu noted a potential for incorrect handshake behavior or denial of service. Updates are available for OpenSSL 4.0, 3.6, 3.5, and 3.4.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.