Re: OpenSSL vulnerability and Client Side Software ?
Reply #9 –
When it is exploited it leads to the leak of memory contents from the server to the client and from the client to the server.
Technically correct.
However it's not the browser which gets attacked and exploited but the server. So it does not make any difference which browser you are using.
As I mentioned before, it's a server-side exploit.
Only if you are using your system as a server/service (most people don't) then your server (using the unfixed OpenSSL) is vulnerable too.
Affected servers/services:
1. should inform their user base
2. should revoke their old certificates after fixing the bug
3. should request their user base to change passwords after the bug was fixed and new certs have been distributed
Wonder how many services will obey those steps.

Edit: BTW, DnD isn't affected
