The flaws exploit the ASN.1 (Abstract Syntax Notation 1) syntax notation used by the SSL (Secure Sockets Layer) and TLS (Transport Layer Security) protocols, which are widely used for exchanging data securely on the internet.
By submitting data that was purposefully constructed, a malicious client could, theoretically, gain control over certain servers running SSL or TLS software.
Oracle could have reduced the risk presented by these bugs had it removed certain features from the OpenSSL software libraries included with its servers, according to Thor Larholm, a senior security researcher with PivX Solutions, a network security consultancy.
More info: [url=http://www.computerweekly.com/articles/article.asp?liArticleID=127127&liFlavourID=1&sp=1]http://www.computerweekly.com/articles/article.asp?liArticleID=127127&liFlavourID=1&sp=1[/url]