Site navigation

Five Things You Need to Know About the OpenSSL Patch 

Ross Kelly

,

OpenSSL Patch
With the OpenSSL patch releasing today, here’s what you need to know.

The OpenSSL project is set to release a critical vulnerability patch today (1st November), marking the second patch of this kind in the project’s history.

In a statement last week, the team announced the patch, which forms part of the OpenSSL 3.0.7 update.

According to the project, the update will provide a fix for a critical vulnerability in the OpenSSL version 3.0 update released last year.

Lotem Finkelstein, Director of Threat Intelligence & Research at Check Point said: “The recent announcement by the OpenSSL project that the upcoming release on November 1st would include a fix for a critical vulnerability put the internet tech community on high alert.

“A critical vulnerability in OpenSSL has the potential to shake the foundations of the encrypted internet and the privacy of all of us. This is indeed a big deal.”

Here’s everything you need to know about the OpenSSL patch.

What is OpenSSL?

OpenSSL is a widely used open source cryptography library. The library is used by the majority of HTTPS websites globally to provide encryption and other security or privacy capabilities.

OpenSSL is regarded as one of the very basic elements of the internet as we know it.

Due to its critical importance, any significant disruption would likely cause havoc for organisations globally.

What is the vulnerability?

At present, complete details of the vulnerability are yet to be shared by the OpenSSL project team.

What we do know is that the vulnerability this aims to fix has been identified as ‘critical’ by the project and affects common configurations.

Which versions of are vulnerable?

OpenSSL version 3.0.0 and higher are vulnerable to the critical security flaw, which is patched in version 3.0.7.

A significant number of operating systems currently use OpenSSL versions 1.1.1 or 1.0.2, meaning that these organisations won’t be impacted. Similarly, organisations using LibreSSL won’t be affected.

Has this happened before?

This isn’t the first time OpenSSL has patched a critical vulnerability. In 2014, security researchers uncovered a serious flaw in the OpenSSL library which came to be known as ‘Heartbleed’.


Recommended


The Heartbleed exploit enabled threat actors to track users online and scrape data entered on affected webpages. At the time, OpenSSL issued an urgent patch. However, many were slow to patch and fell prey to the exploit.

Web servers globally were severely impacted by Heartbleed, and to this day it is estimated that more than 90,000 servers still remain vulnerable.

What happens next?

Cybersecurity company Check Point has warned that organisations should “stay alert” ahead of the patch. Meanwhile, the OpenSSL project advised organisations to prepare to patch as soon as possible after 3.0.7 is released.

Finkelstein added: “While we will have to wait and read what the OpenSSL team has to share on Tuesday, we would like to urge all organizations to improve their visibility of the different apps and web services they use or provide and the OpenSSL version they run.

“This is not an easy task, but on Tuesday we will need to make sure we are familiar with our weak points and act to prevent the coming attack.”


DIGIT Expo 2022 | Join the Conversation

DIGIT Expo is Scotland’s largest gathering of senior technology personnel and an unmissable opportunity for knowledge exchange, networking and business opportunity.

The conference will feature an array of tech leaders, innovators and world-class speakers exploring key themes such as AI, DevOps, cyber security, digital leadership, cloud computing, Web3 and data innovation.

Find out more at: www.digit-expo.com

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data