5 ms·
Seeing as it's static, it's not part of the public API. Apparently it was used in Ruby at one point: https://groups.google.com/forum/#!topic/mailing.openssl.dev
by pipeep 12y ago
Seeing as it's static, it's not part of the public API. Apparently it was used in Ruby at one point: https://groups.google.com/forum/#!topic/mailing.openssl.dev/7kcdEa5lpLI https://groups.google.com/forum/#!topic/mailing.openssl.dev/...
I think it's probably a piece of dead code at this point, but there might be some legacy stuff using it (with an old version of OpenSSL), which could lead to a vulnerability. Regardless, the function should probably be rewritten or removed.
EDIT: It looks like the latest version of Ruby (MRI) actually copied this function from OpenSSL so they could keep using it: https://github.com/ruby/ruby/blob/1aa54bebaf274bc08e72f9ad3854c7ad592c344a/ext/openssl/ossl_ssl_session.c#L76 https://github.com/ruby/ruby/blob/1aa54bebaf274bc08e72f9ad38...
- chomp 12y agoYeah, I'm thinking it's dead code. It's not exposed in modern OpenSSLs, and I can't find any services we use (Pure-FTP, httpd, etc) that use this function. OpenSSL devs should probably remove this code.
- pipeep 12y agoIt looks like there's some github projects using it: https://github.com/search?q=SSL_SESSION_cmp&ref=cmdform&type=Code https://github.com/search?q=SSL_SESSION_cmp&ref=cmdform&type...
- pipeep 12y agoI made a patch to ruby swapping the memcmp for CRYPTO_memcmp, which should be constant-time. I'm checking to see that I didn't break the build, after which I'll make a pull request to https://github.com/ruby/ruby https://github.com/ruby/ruby. Then it'll be up to the ruby developers, who probably have better insight into this than me, to accept or decline it. EDIT: For anyone interested: https://github.com/ruby/ruby/pull/591 https://github.com/ruby/ruby/pull/591
- petermalone 12y agoThe current version of Android also uses it.
- pipeep 12y agoLink?
- petermalone 12y agohttps://android.googlesource.com/platform/external/openssl/+/android-4.4.2_r2/ssl/ssl_lib.c https://android.googlesource.com/platform/external/openssl/+...
- pipeep 12y agoIt's marked as static and isn't used anywhere there, so it's not an issue: they have an up-to-date version of upstream OpenSSL.
- petermalone 12y agoAh - good to know. Cheers!