NOOB2ROOT

CVE watch CVE-2014-0160

Heartbleed: memory disclosure in OpenSSL

A missing bounds check in the OpenSSL TLS heartbeat extension let anyone read up to 64KB of server memory per request — including private keys.

Severity
7.5
high
Vendor
OpenSSL
Disclosed
7 Apr 2014
Affected
OpenSSL 1.0.1 through 1.0.1f

CVSS breakdown

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Analysis

Placeholder analysis — replace before publishing.

References