logo

Heart Attack? Fixes For More Critical Holes In OpenSSL

ID: 1869440d-f499-59c2-9461-8b1e62b2a46f

STIX ID: report--1869440d-f499-59c2-9461-8b1e62b2a46f

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2014-06-05

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

OpenSSL released patches for six vulnerabilities—two flagged as critical—including a TLS/SSL MITM flaw (CVE-2014-0224) and a DTLS invalid fragment issue potentially enabling remote code execution (CVE-2014-0195). The advisory warns that SSL VPNs and DTLS-using applications (e.g., VoIP, WebRTC) may be affected and urges immediate updates for OpenSSL 0.9.8, 1.0.0 and 1.0.1, while noting these issues are generally less severe than Heartbleed due to constrained exploit conditions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.