Overview
CVE-2014-0160 failed to bounds-check a heartbeat request, so a client could ask the server to echo back far more memory than it had sent.\nAny TLS private key, session cookie or credential resident in that memory was potentially exposed, and nothing in the logs showed it happening.\nIt forced a global certificate-revocation and reissue effort.
Indicators of Compromise
Signals that suggest this is present on a system.
- OpenSSL 1.0.1 through 1.0.1f in service
- Certificates issued before April 2014 never rotated
- Heartbeat extension enabled