Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
The Hacker News
3 weeks ago

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

By info@thehackernews.com (The Hacker News)

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.