The Heartbleed Bug - What versions of the OpenSSL are affected?

Reference: The Heartbleed Bug

What versions of the OpenSSL are affected?

Status of different versions:

  1. OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable
  2. OpenSSL 1.0.1g is NOT vulnerable
  3. OpenSSL 1.0.0 branch is NOT vulnerable
  4. OpenSSL 0.9.8 branch is NOT vulnerable

Bug was introduced to OpenSSL in December 2011 and has been out in the wild since OpenSSL release 1.0.1 on 14th of March 2012. OpenSSL 1.0.1g released on 7th of April 2014 fixes the bug.

1 Like

Also, you can test any server you use for the heartbleed bug at this excellent web site:

SSL Server Test

If any of the oracle products use openssl library can we check if that is impacted?

Best regards,
Vishal

You can easily Google terms like Oracle heartbleed to get an answer to your question.