Hacker News new | past | comments | ask | show | jobs | submit login

How has LibreSSL stood up lately to the relatively frequent CVEs in OpenSSL the past few months? I know the initial months were a frenzy of removing garbage and classes of problems (#yadf) that preempted a few CVEs, but I haven't been paying attention to the commit logs to know if it was also susceptible to them.



A quick look through the release notes: https://www.libressl.org/releases.html seems to indicate that they've only been affected by six CVEs since October 2015.

I haven't followed LibreSSL recently, but previously many of the CVEs that affected OpenSSL are for features that LibreSSL ripped out.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: