Sunday, March 19, 2023
  • Advertise With Us
  • Write For Us
  • Contact Us
  • About Us
  • Editorial Calendar
Download Latest Issue - Free!
The Cyber Express
GISEC
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Gamekaking Data Breach

    Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

    Medusa Ransomware Group

    Medusa Ransomware Group Targets National Institute of Ocean Technology

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Clop Ransomware Group Adds Hitachi Energy

    Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

    Onex Data Exposed

    Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

    Euler Finance Cyber Attack

    Euler Finance Cyber Attack Hackers Returns $165k to Victim

    Independent Living Systems Data Breach

    Independent Living Systems Data Breach Puts 4.2 Million Individuals at Risk

    Loyola University Data Breach

    Loyola University Data Breach, Hackers Claim to Have Access to Personal Student Data

    Pornhub

    Pornhub Removes Wagner Ad Recruiting Soldiers For Russian War

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Cyble Among Top 50 Emerging Companies

    Cyble Among Top 50 Emerging Companies Across Governance Risk & Compliance Solutions Sector

    Call and Contact Center Expo

    The Countdown Begins: The Call and Contact Center Expo Las Vegas 2023 is Officially Here!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Gamekaking Data Breach

    Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

    Medusa Ransomware Group

    Medusa Ransomware Group Targets National Institute of Ocean Technology

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Clop Ransomware Group Adds Hitachi Energy

    Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

    Onex Data Exposed

    Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

    Euler Finance Cyber Attack

    Euler Finance Cyber Attack Hackers Returns $165k to Victim

    Independent Living Systems Data Breach

    Independent Living Systems Data Breach Puts 4.2 Million Individuals at Risk

    Loyola University Data Breach

    Loyola University Data Breach, Hackers Claim to Have Access to Personal Student Data

    Pornhub

    Pornhub Removes Wagner Ad Recruiting Soldiers For Russian War

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Cyble Among Top 50 Emerging Companies

    Cyble Among Top 50 Emerging Companies Across Governance Risk & Compliance Solutions Sector

    Call and Contact Center Expo

    The Countdown Begins: The Call and Contact Center Expo Las Vegas 2023 is Officially Here!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

OpenSSL Releases Update to Fix High Severity Vulnerability, And More

OpenSSL, one of the most widely used encryption libraries globally, has just released three new security updates to cover eight vulnerabilities.

Chandu Gopalakrishnan by Chandu Gopalakrishnan
February 8, 2023
in Firewall Daily
0
OpenSSL Releases Update
621
SHARES
3.5k
VIEWS
Share on LinkedInShare on Twitter

OpenSSL, one of the most widely used encryption libraries globally, has just released three new security updates to cover eight vulnerabilities.  

The updates cover the two current open-source versions that the organization supports, as well as the outdated 1.0.2 version series, which is only available to customers who pay for premium support.  

You might also like

Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

Medusa Ransomware Group Targets National Institute of Ocean Technology

FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

The updated versions of OpenSSL 3.0 series will be version 3.0.8, OpenSSL 1.1.1 series will be version 1.1.1t, and OpenSSL 1.0.2 series will be version 1.0.2zg.  

“If you’re wondering why the older versions have three numbers plus a letter at the end, it’s because the OpenSSL project used to have four-part version identifiers, with the trailing letter acting as a counter that could support 26 sub-versions,” said the Sophos analysis report of the patches. 

“As you can see from what’s happened to version 1.0.2, 26 sub-versions turned out not to be enough, leaving a quandary of what to do after version Z-for-Zulu: go back to Alpha-Alpha, which confusingly breaks alphabetic ordering, or just stick with Z-for-Zulu and start a sub-sub-version cycle of A-to-Z. 

The older versions had a three-number and a letter system, but the OpenSSL team has now adopted the X.Y.Z three-number versioning system, with the current version being 3.0 and sub-version 8. 

OpenSSL vulnerabilities 

There are eight CVE-numbered bug fixes in total, with seven of them caused by memory mismanagement issues.  

Like OpenSSH, OpenSSL is written in C and managing memory allocation and deallocation can be challenging.  

“Unfortunately, even experienced programmers can forget to match up their malloc() calls and their free() calls correctly, or can lose track of which memory buffers belong to what parts of their program,” said the Sophos report. 

The seven memory-related bugs are: CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4203, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401, affecting all or specific versions of OpenSSL. 

Vulnerability CVE-2023-0286 is rated high and all others are rated moderate. 

What troubles OpenSSL? 

A NULL dereference occurs when an attempt is made to use the number 0 as a memory address. This usually indicates an incorrectly initialized storage variable since zero is never considered a valid data storage location.  

Most modern operating systems have labelled the first few thousand bytes of memory as unusable to prevent hardware-level errors.  

When a program tries to access the zero page, the operating system will shut it down. This type of bug is prone to denial-of-service attacks as a cybercriminal can deliberately trigger the vulnerability and cause the program to crash repeatedly.  

An invalid pointer dereference is similar, but it means trying to access an address that was not assigned. 

OpenSSL and earlier bugs 

The previous major OpenSSL patch came in November 2022, when OpenSSL cryptography library released an update to fix a critical vulnerability.  

That was only the second time the project has faced a flaw classified as ‘critical,’ with the first being the well-known Heartbleed vulnerability (CVE-2014-0160).  

Heartbleed was a memory handling bug that allowed attackers to access sensitive information from vulnerable servers. 

The November patch (OpenSSL 3.0.7) affected only OpenSSL version 3.0. However, OpenSSL version 3.0.x was only released in 2021 and may limit the extent of the problems caused by the announcement.  

One security expert from Google suggested then, based on recent software commits and a blog post by the OpenSSL team, that the update might relate to a denial-of-service issue.

Even Mark Cox, VP of Security at the Apache Software Foundation, tweeted about that as a fix for a “critical CVE”, raising concerns. However, it turned out to be less severe than expected.  

Although the two email security bugs were rated 8.8 and considered high, they only affect OpenSSL versions 3.0.0 to 3.0.6. If you’re using OpenSSL 1.1.1 or 1.0.2, there’s no need to worry. 

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: OpenSSLOpenSSL Releases Update
Previous Post

Weee! Data Breach: 11M User Records Leaked By Unknown Threat Actor

Next Post

LockBit Ransomware Gang Claims Italian Winery Cantina Tollo as Victim

Chandu Gopalakrishnan

Chandu Gopalakrishnan

Executive Editor, The Cyber Express

Related Posts

Gamekaking Data Breach
Dark Web News

Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

by Ashish Khaitan
March 18, 2023
Medusa Ransomware Group
Data Breach News

Medusa Ransomware Group Targets National Institute of Ocean Technology

by Ashish Khaitan
March 18, 2023
BreachForums
Compliance

FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

by Chandu Gopalakrishnan
March 18, 2023
Clop Ransomware Group Adds Hitachi Energy
Data Breach News

Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

by Vishwa Pandagle
March 18, 2023
Onex Data Exposed
Data Breach News

Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

by Vishwa Pandagle
March 17, 2023
Next Post
Italian Winery Cantina Tollo

LockBit Ransomware Gang Claims Italian Winery Cantina Tollo as Victim

Latest Issue is Out. Subscribe Now

Women in Cybersecurity

Download Now

CRIL


Follow Us On Google News

Never miss an update. Subscribe!

* indicates required

Top 10 Cybersecurity Jobs

Categories

About The Cyber Express

The Cyber Express

Cyber Security News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

Follow The Cyber Express

Contact

For editorial queries: [email protected]

For marketing, PR & media partnerships: [email protected]

For media kit and digitals sales: [email protected]

For Sponsorship/Event Partnership: [email protected]

For Conferences related information: [email protected]

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

Tel: (678) 578-8838

Events: +1 (678) 578-4140

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Tel: (678) 578-8838

Events: +1 (678) 578-4140

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Firewall Daily
  • Business News
  • Cyber Essentials
  • Features
  • Cyber Security Magazine
  • Events
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.