THEMETASEC

Cybersecurity News, Aggregated

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

The Hacker News · 4 hours ago Breach

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

Read full story at The Hacker News →