Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In addition to OpenSSL's Heartbleed, nginx had its own functionally-identical "Heartbleed" bug in its header parsing. Exact same impact.

(I don't think anyone made a big deal about it at the time; I knew about it because our team at Matasano discovered it independently just an hour or two before someone else filed the bug).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: