Security News > 2020 > April > High-Severity Vulnerability in OpenSSL Allows DoS Attacks

High-Severity Vulnerability in OpenSSL Allows DoS Attacks
2020-04-21 14:01

An update released on Tuesday for OpenSSL patches a high-severity vulnerability that can be exploited for denial-of-service attacks.

The vulnerability impacts OpenSSL versions 1.1.1d, 1.1.1e and 1.1.1f, and it has been patched with the release of version 1.1.1g. Older versions 1.0.2 and 1.1.0, which no longer receive security updates, are not impacted by the flaw.

This is the first vulnerability patched in OpenSSL in 2020.

As SecurityWeek reported a few months ago, OpenSSL security has evolved a great deal since the disclosure of the Heartbleed vulnerability back in 2014.

While nearly a dozen critical and high-severity vulnerabilities were found in OpenSSL between the disclosure of Heartbleed and the end of 2016, in 2017 there was only one high-severity flaw identified, and in 2018 and 2019 all the patched issues were low or medium severity.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/NtUw6iKPJDQ/high-severity-vulnerability-openssl-allows-dos-attacks

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Openssl 2 12 92 51 16 171