oss-sec mailing list archives

Re: OpenSSL 1.0.1 TLS/DTLS hearbeat information disclosure CVE-2014-0160


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Tue, 8 Apr 2014 22:51:41 -0700

I find it somewhat perplexing that Codenomicon apparently had time to
register the vanity domain two days before pinging the vendor (or
rather unnecessarily, having CERT do it on their behalf).

Domain Name: HEARTBLEED.COM
Creation Date: 2014-04-05 15:13:33
[...]
Mon, 07 Apr 2014 ~15:30: NCSC-FI reports issue to OpenSSL

/mz


Current thread: