HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
OpenSSL Servers Left Vulnerable to Memory-Consuming Attack A newly discovered vulnerability in OpenSSL, dubbed HollowByte, allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on vulnerable servers with just an 11-byte malicious payload. The issue has been silently patched by the OpenSSL team and backported to older releases. The problem lies in the way vulnerable … Read more