Published in News

OpenSSL promises new fixes

by on17 March 2015


Full of bugs

The OpenSSL project team has confirmed that it will make available releases on March 19th to fix a number of security defects, classified as 'high' severity. 

Gavin Millard, Technical Director of Tenable Network Security believes that the vulnerabilities involved effect OpenSSL 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf.

“With the contributors to the OpenSSL project staying tight lipped apart from stating it will be classified as “High Severity”, it would be prudent for organisations to identify all systems affected in advance of the patch to deploy the updates if required,” he said.

Fears are that the vulnerabilities will be just as bad as Heartbleed, which is still alive and kicking on unupdated servers. Millard said that hopefully this bug will be less severe than Heartbleed but, until Thursday, only a few will know.

Rate this item
(5 votes)