SHARE
Facebook X Pinterest WhatsApp

Heartbleed 2.0? OpenSSL Warns of Second-Ever Critical Security Flaw

The OpenSSL project this week announced plans to release version 3.0.7 on November 1 to patch a critical security flaw affecting versions 3.0 and later. Co-founder Mark J. Cox noted it’s only the second critical patch “since we started rating flaws back in 2014.” OpenSSL identifies critical issues as those affecting common configurations and likely […]

Written By
thumbnail Jeff Goldman
Jeff Goldman
Oct 28, 2022
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The OpenSSL project this week announced plans to release version 3.0.7 on November 1 to patch a critical security flaw affecting versions 3.0 and later. Co-founder Mark J. Cox noted it’s only the second critical patch “since we started rating flaws back in 2014.”

OpenSSL identifies critical issues as those affecting common configurations and likely to be exploitable, with examples including “significant disclosure of the contents of server memory (potentially revealing user details), vulnerabilities which can be easily exploited remotely to compromise server private keys or where remote code execution is considered likely in common situations.”

ANALYGENCE senior vulnerability analyst Art Manion’s observed that November 1, All Saints’ Day, is unfortunately a public holiday in several EU countries, and Cox conceded, “We didn’t realize that. It’s pretty hard to avoid every holiday everywhere.”

See the Top Code Debugging and Code Security Tools

What to Do About OpenSSL Now

Software developer Carlos Solís asked, “So what temporary measures should be applied to our servers while the embargo is lifted?” Cox bluntly responded, “We’ve not provided any other information at the time.”

Still, Sophos researchers suggested one crucial step to take before next Tuesday, advising, “All users of OpenSSL should use this time to inventory instances of OpenSSL and prepare for immediate patching when this is released.”

Cox agreed: “This is good advice. If you know in advance where you are using OpenSSL 3.0+ and how you are using it then when the advisory comes you’ll be able to quickly determine if or how you’re affected and what you need to patch.”

To assist in that process, SANS dean of research Johannes B. Ullrich has posted a list of the OpenSSL versions for more than 25 operating systems, noting, “MacOS, by default, uses LibreSSL, not openssl installed. But openssl may be installed later by other software like Homebrew and MacPorts.”

Also read: Is the Answer to Vulnerabilities Patch Management as a Service?

The Next Heartbleed?

Venafi container product lead Mattias Gees said the announcement calls to mind highly impactful flaws like Heartbleed and Log4Shell. “Heartbleed had a significant impact on all operations teams worldwide, and since then IT infrastructure has become 10 times more complicated,” he said.

“When Heartbleed was discovered, the majority of IT organizations were using dedicated hardware or virtual machines (VMs),” Gees said. “But now we are in the Cloud Native era, which has created advanced containers and serverless architectures. The attack vector has become a lot larger, and rather than just having to examine their VMs, organizations need to start preparing to patch all their container images in response to this announcement.”

Organizations that have already audited their dependencies in response to Log4Shell, Gees said, will be well-positioned to roll out a fix as efficiently as possible.

The fact that the flaw only impacts version 3.0 and later, he added, should at least limit its potential impact. “But platform engineering teams should keep investing in better auditing of their environments and their dependencies for the next threat, which is always just around the corner.”

Read next:

thumbnail Jeff Goldman

eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet writer since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.

Recommended for you...

SQL Injection Prevention: 6 Ways to Protect Your Stack
Matt Gonzales
Jul 9, 2025
Microsoft Defender vs Bitdefender: Compare Antivirus Software
Jenna Phipps
May 27, 2025
Bitwarden vs Dashlane: Comparing Password Managers
Jenna Phipps
May 14, 2025
What Is Malware? Definition, Examples, and More
Davin Jackson
Feb 10, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.