Multiple vulnerabilities in OpenSSL have been reported by security researchers from different companies, which, if exploited, could lead to information leakage, system malfunction, or downgrade to a lower version of the security protocol.
Researchers from Google, LogMeIn, Codenomicon, and NCC Group reported the issues, and some of them also provided a much-needed solution.
One of the vulnerabilities in the OpenSSL SSL/TLS server code, discovered by David Benjamin and Adam Langley from Google, could allow a potential attacker to use the less secure TLS 1.0 instead of a newer version of the protocol.
This will happen when a "ClientHello" message is delivered to a server during a man-in-the-middle attack, forcing the downgrade by changing the client's TLS records, even if the client and server include support for a more recent version of the protocol.
Denial of service (DoS) attacks could also be carried out by sending malcrafted DTLS packets that would lead to memory leaks. The same could be achieved when processing DTLS messages.
It's worth noting that none of the issues found by security researchers are anywhere near the criticality of the Heartbleed bug, which was disclosed by Codenomicon in April of this year. Even so, administrators should upgrade to the latest version of the OpenSSL library (0.9.8zb, 1.0.0n, or 1.0.1i) as soon as possible.

