Theres a new bug in OpenSSL, much to everyones dismay, and this one allows attackers to see and modify traffic between an OpenSSL client and an OpenSSL server.
While this may sound terrible, its actually nowhere near as bad as Heartbleed was. In fact, the issue is limited because it only affects specific versions of OpenSSL server and youd need to use the same server software on a client application.
According to the announcement, OpenSSL clients are vulnerable …