Executive brief
The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g fail to properly handle Heartbeat Extension packets. This allows remote attackers to trigger a buffer over-read and obtain sensitive process memory, including private cryptographic keys and passwords, commonly known as the Heartbleed bug.
Affected products
- OpenSSL OpenSSL 1.0.1 before 1.0.1g
Timeline
- 2022-05-04: disclosed: NVD publication date provided in advisory.
- exploited: Reported as exploited in the wild.