Vulnerability Bulletins

DSA-2896 openssl - security update

   
Affected software Debian
 
A vulnerability has been discovered in OpenSSLs support for theTLS/DTLS Heartbeat extension. Up to 64KB of memory from either client orserver can be recovered by an attacker. This vulnerability might allow anattacker to compromise the private key and other sensitive data inmemory.

More info:

https://www.debian.org/security/2014/dsa-2896