> True. Thanks for the quick reply.
> https://www.openssl.org/news/changelog.html
> 1.0.1 introduced the heartbeat support.
> 1.0.0 and earlier are fortunate in that they didnt have it.....but then they 
> didnt have things to stop you from being BEASTed so some you win, some you 
> lose. ;)
As you can read in the above change log, heartbeat support was
introduced in version 1.0.1 of openssl. Does this mean that also the bug
was introduced with this version in March 2012, or was it later?

What is the exact bug, can someone show a svn/git diff of the first
source version having the bug?

Is it possible that the bug was introduced with intention (to make
use of it later)?

Here in Germany in the news we have rumor, that the bug was used by NSA,
of course the American Goverment says no.



