Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Staying ahead of OpenSSL vulnerabilities

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Nick Sullivan
Word Count
281
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

On April 7, 2014, a vulnerability in OpenSSL 1.0.1 was announced, allowing attackers to reveal up to 64kB of memory to connected clients or servers (CVE-2014-0160). CloudFlare fixed this issue before it went public and all sites using their SSL service were automatically protected. OpenSSL is the core cryptographic library used by CloudFlare for SSL/TLS connections, with a large deployment on the internet. They encourage others running servers that use OpenSSL to upgrade to version 1.0.1g or recompile with the OPENSSL_NO_HEARTBEATS flag enabled for protection against this vulnerability. This bug fix exemplifies responsible disclosure, where stakeholders are given a chance to fix issues before public disclosure, helping keep the internet safe.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.