May 5, 2022, 7:26 p.m. | brooke.crothers

Security Boulevard securityboulevard.com

OpenSSL Patches New Bug Targeting Encryption [Lessons from Heartbleed]

brooke.crothers

Thu, 05/05/2022 - 12:26




What is the new OpenSSL vulnerability?

CVE-2022-0778 is described as an infinite loop DoS attack discovered by Google vulnerability researcher Tavis Ormandy. A flaw in the encryption algorithm used to underpin OpenSSL was exploited, triggering an infinite number of requests when certain input value(s) are used. OpenSSL relies on Elliptic Curve (EC) cryptography, which is faster and more elegant than the older RSA, and …

bug encryption heartbleed openssl patches targeting

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Intermediate Security Engineer, (Incident Response, Trust & Safety)

@ GitLab | Remote, US

Journeyman Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Project Manager II - Compliance

@ Critical Path Institute | Tucson, AZ, USA

Junior System Engineer (m/w/d) Cyber Security 1

@ Deutsche Telekom | Leipzig, Deutschland