Deprecated: Constant PDO::MYSQL_ATTR_INIT_COMMAND is deprecated since 8.5, use Pdo\Mysql::ATTR_INIT_COMMAND instead in /htdocs/wire/core/WireDatabasePDO.php on line 282

Deprecated: Constant PDO::MYSQL_ATTR_INIT_COMMAND is deprecated since 8.5, use Pdo\Mysql::ATTR_INIT_COMMAND instead in /htdocs/wire/core/WireDatabasePDO.php on line 283

Deprecated: session_set_save_handler(): Providing individual callbacks instead of an object implementing SessionHandlerInterface is deprecated in /htdocs/wire/core/WireSessionHandler.php on line 51

Deprecated: Using null as an array offset is deprecated, use an empty string instead in /htdocs/wire/core/WireArray.php on line 610
Golden Frog Services Safe From Latest OpenSSL Vulnerability | VyprVPN
Golden Frog Services Safe From Latest OpenSSL Vulnerability

Product

Golden Frog Services Safe From Latest OpenSSL Vulnerability

July 8, 2015

by Philip Molter, co-CTO Golden Frog

OpenSSL announced today a high-severity vulnerability in the OpenSSL library (CVE-2015-1793). The vulnerability allows attackers to forge certificates and, in some cases, have those certificates trusted. For example, the bug could allow a malicious server to represent itself as a Golden Frog server to vulnerable clients.

We wanted to let all our Golden Frog users know that our services and clients are not vulnerable to this bug. The bug affects only very recent versions of OpenSSL, and our servers and software use stable versions of OpenSSL that only include backported security fixes, not new features like the one that introduced this bug. In addition, where possible, our apps leverage SSL libraries provided by the customer’s operating system, and almost all standard OS releases are not vulnerable to this release. You should only be concerned if you run a custom system on which you have installed a very recent version of OpenSSL yourself. In that case, you should update your version of OpenSSL to the latest patched release.

Since the Heartbleed vulnerability, OpenSSL has taken to pre-announcing high and critical severity bugfixes. Because of this, some media outlets are hyping these upcoming releases as “the next Heartbleed.” So far, that hasn’t been the case, and it is certainly not the case here.

For more information about the bug, check the official OpenSSL release or this followup article by The State of Security.

30-Day Money-Back Guarantee

Get VyprVPN Now