Hacker News new | past | comments | ask | show | jobs | submit login

    OpenSSL announced several issues today that also affect LibreSSL.

    - Memory corruption in the ASN.1 encoder (CVE-2016-2108)
    - Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
    - EVP_EncodeUpdate overflow (CVE-2016-2105)
    - EVP_EncryptUpdate overflow (CVE-2016-2106)
    - ASN.1 BIO excessive memory allocation (CVE-2016-2109)

    Thanks to OpenSSL for providing information and patches.
http://marc.info/?l=openbsd-announce&m=146228598930416&w=2

https://twitter.com/bob_beck/status/727478594591543296




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: