logo

New OpenSSL Flaw Is No Heartbleed

ID: cde50017-21c4-58e9-9ec2-6791fdbd4ad6

STIX ID: report--cde50017-21c4-58e9-9ec2-6791fdbd4ad6

Feed Name: Security Ledger

Threat Score
30/100

Date Published: 2015-07-09

Date Updated: 2026-05-06

Author: Robert Vamosi

...
...

OpenSSL disclosed a high-severity certificate-validation flaw (CVE-2015-1793) that can enable forged certificates by falling back to an alternative certificate chain when initial chain building fails; affected releases include OpenSSL 1.0.2b/1.0.2c and 1.0.1n/1.0.1o and users are advised to upgrade to patched versions (1.0.2d or 1.0.1p). The report emphasizes limited real-world impact because common browsers and SSL derivatives typically do not use the affected OpenSSL builds and successful exploitation requires both access to a vulnerable client and delivery of the forged certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.