← Back to the feed

~/article/openssl-fixes-high-severity-dtls-flaw-that-can-leak-heap-memory-unencryp-1rwya8
lowSource: The Hacker News

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/openssl-fixes-high-severity-dtls-flaw-that-can-leak-heap-memory-unencryp-1rwya8