In the Open

Heartbleed

  • SSL V1.0.1 and V1.0.1f
  • Client sends msg, msglength
  • If msg is 0 and the msglength is longer, return from server is arbitrary memory content

  • Heartbleed