April 7, 2014
Heartbleed OpenSSL vulnerability disclosed
Researchers disclosed CVECommon Vulnerabilities and Exposures — a public dictionary of known security flaw identifiers.-2014-0160 on April 7, 2014 — the Heartbleed bug in OpenSSLOpen-source library implementing TLS, SSL, and general-purpose cryptography — ubiquitous in HTTPS servers.'s TLSTransport Layer Security — encryption that protects data in transit on the web and networks. heartbeat extension that leaked server memory including private keyA secret cryptographic key kept by one party — used to decrypt or sign data; must never be shared.s and passwords.
What it was for
Heartbleed forced mass certificate rotation, OpenSSLOpen-source library implementing TLS, SSL, and general-purpose cryptography — ubiquitous in HTTPS servers. governance reform, and the creation of LibreSSL and BoringSSL forks. Any site using OpenSSLOpen-source library implementing TLS, SSL, and general-purpose cryptography — ubiquitous in HTTPS servers. 1.0.1 needed emergency patching — a reminder that a single C bug in ubiquitous crypto libraries compromises the entire web trust model.
Why it's here
Heartbleed was the biggest TLSTransport Layer Security — encryption that protects data in transit on the web and networks. library vulnerability since SSL's commercialization.
Why it mattered
It triggered global cert reissues and scrutiny of underfunded crypto infrastructure.
What it solved
Nothing until patched — attackers could read 64 KB chunks of server memory without authentication.
Media
- ImageHeartbleed
Leena Kurjenniska / Codenomicon 2014, CC0, via Wikimedia Commons
Related
- OpenBSD team releases OpenSSHDecember 1, 1999
- Log4Shell vulnerability disclosedDecember 9, 2021
- Stuxnet worm discovered targeting industrial systemsJune 17, 2010