CVE-2014-0160 | OpenSSL up to 1.0.2 TLS/DTLS Heartbeat ssl/t1_lib.c dtls1_process_heartbeat/dtls1_process_heartbeat memory corruption (VU#720951 / EDB-32745)
A vulnerability, which was classified as very critical, was found in OpenSSL up to 1.0.2. This affects the function dtls1_process_heartbeat/dtls1_process_heartbeat in the library ssl/t1_lib.c of the component TLS/DTLS Heartbeat Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2014-0160. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to upgrade the affected component.