4 ms·
LibreSSL hasn't improved anything. Deleting all the code that was #ifdef'd out for old platforms might make you feel good, but it doesn't actually help security
by dadrian 6y ago
LibreSSL hasn't improved anything. Deleting all the code that was #ifdef'd out for old platforms might make you feel good, but it doesn't actually help security because none of the code was compiled anyway.
- dijit 6y agoThis does a great disservice to the work done by the OpenBSD guys. For one thing they removed the home-grown memory allocator, which prevented a lot of issues and allowed debugging tools to notice memory corruption issues.
- 77pt77 6y ago> allowed debugging tools to notice memory corruption issues You mean like the bug debian introduced here[1]? [1] https://www.debian.org/security/2008/dsa-1571 https://www.debian.org/security/2008/dsa-1571
- GoblinSlayer 6y agoThey also added a nice API, but they don't have manpower for a substantial refactoring.
- brobdingnagians 6y agoHonest question: does LibreSSL have this same vulnerability? If they do, fair comment. If not, then they obviously changed something, ipso facto.
- hyperman1 6y agoGood question. I found this, release 17-03-2021, that seems to be the same bug. So yes, they had the same vulnerability. https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.2.5-relnotes.txt https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.2.5-... Update: AAAACHCHC!! Dates! Always the dates. OK, Very well. For your viewing pleasure: * Americans: Patch was released on 03-17-2021 * Europeans: Patch was released on 17-03-2021 * World inhabitants: Patch was released on 2021-03-17
- TimWolla 6y agoThis is the fix for the LibreSSL issue [1]: https://github.com/libressl-portable/openbsd/commit/5f00b800749f246861e892a17d9012bd25fc06ba https://github.com/libressl-portable/openbsd/commit/5f00b800... This is the fix for the OpenSSL issue: https://github.com/openssl/openssl/commit/02b1636fe3db274497304a3e95a4e32ced7e841b https://github.com/openssl/openssl/commit/02b1636fe3db274497... They don't appear to be related to me. One is a UAF, the other is a NULL pointer dereference. [1] The LibreSSL issue was found by HAProxy's continuous integration pipeline: https://github.com/haproxy/haproxy/issues/1115 https://github.com/haproxy/haproxy/issues/1115. Disclosure: I'm a community contributor of HAProxy, I help maintain the issue tracker and I took part in debugging the issue.
- hyperman1 6y agoThey did more than that. See e.g. this slide: If you use normal coding patterns, then normal linting tools can notice the bugs. The openssl code was hiding the truth from these tools, for no reason. https://www.openbsd.org/papers/bsdcan14-libressl/mgp00014.html https://www.openbsd.org/papers/bsdcan14-libressl/mgp00014.ht...