THE OpenSSL HollowByte vulnerability, discovered by the Okta Red Team, allows remote attackers to crash web servers with a minimal payload of just eleven bytes, leading to out-of-memory conditions. This flaw affects crucial server software like NGINX and Apache. The attack exploits the memory management of OpenSSL during the initial secure connection, creating memory fragmentation until the server crashes. While patched versions exist (4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21), unpatched systems remain vulnerable. Security teams should urgently update their software to prevent potential disruptions.
OpenSSL HollowByte flaw lets 11 byte attacks crash NGINX, Apache
CyberSIXT Evidence Panel
Primary Source
sec.okta.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
HollowByte bug lets attackers crash OpenSSL with 11-byte payload
cybersixt.com
-
OpenSSL HollowByte flaw lets 11 byte attacks crash NGINX, Apache
securityonline.info
-
OpenSSL's HollowByte flaw lets tiny payload crash servers
cybersixt.com