The survey found that nearly half of polled Web servers ran a version of OpenSSL that could be remotely exploited to bypass the server's security. (The 50,000 servers queried in the study were limited to those computers that returned a valid OpenSSL signature.) Other versions had lesser vulnerabilities. The survey did come with one major caveat: Many Linux distributions that include the software don't update the version numbers, making it falsely appear that the software is vulnerable.
- More from News.com on this story's topics
Security
Open source
See more CNET content tagged:
OpenSSL,
survey,
Web server,
patch management,
server
... or log in manually to your email client and click the link in our email. Once you have confirmed your registration, please log in.

