4 ms·
Exactly. I don't have any evidence to back up my suspicion. If the evidence exists, it exists in a locked safe somewhere at Ft Meade (or other place) and in t
by java-man 7y ago
Exactly. I don't have any evidence to back up my suspicion. If the evidence exists, it exists in a locked safe somewhere at Ft Meade (or other place) and in the brains of a very few people.
I can feel what is known as code smell. So, let's develop a new feature in the most widely used security library. The very first thing that must be done is to sanitize network input. This is the first thing I would expect to be done by a seasoned developer. The lack of this check is suspicious. It could be an honest mistake, of course - we all make mistakes, and I am sure I've made my share of idiotic changes. But this isn't something I would expect about OpenSSL. I agree with @nickpsecurity, "many oddities".
Commit that introduced the vulnerability:
https://git.openssl.org/gitweb/?a=commit&h=4817504d069b4c5082161b02a22116ad75f822b1&p=openssl.git https://git.openssl.org/gitweb/?a=commit&h=4817504d069b4c508...
Fix:
https://github.com/openssl/openssl/commit/96db9023b881d7cd9f379b0c154650d6c108e9a3 https://github.com/openssl/openssl/commit/96db9023b881d7cd9f...