Toutes les vulnérabilités
HIGHInfraexploited in the wild

CVE-2014-0160

OpenSSL · OpenSSL (TLS/DTLS heartbeat extension)

Résumé

A missing bounds check in OpenSSL's TLS/DTLS heartbeat extension lets a remote attacker request more data than they supplied, causing the server to return up to about 64KB of adjacent process memory per request. Repeated requests can leak private keys, session cookies, usernames, and passwords without leaving traces. It affected a large share of HTTPS servers on the internet at disclosure. The Community Health Systems breach, theft of roughly 4.5 million patient records in 2014, was attributed to Heartbleed exploitation of a vulnerable device.

Références

Vulnérabilités liées

Tout Infra →