5 ms·
This announcement narrows down the proximate cause of the bug to changes introduced in the 1.0.1 line. Assuming this is a defect in a new feature (rather than
by ctz 11y ago
This announcement narrows down the proximate cause of the bug to changes introduced in the 1.0.1 line.
Assuming this is a defect in a new feature (rather than a bugfix which went awry) that means there's a fairly limited number of culprits: SCTP, DTLS-SRTP, NPN, RSA-PSS, TLS v1.1, TLS v1.2 or SRP.
FWIW, I'll take SRP for 300.
- tptacek 11y agoThere was a sort-of interesting memory corruption flaw in OpenSSL 1.0.1 SRP (it was interesting because the corrupted copy was implied in bignum operations, so you had to squint at look at OpenSSL BN code as string copies). I remember when our team found it, we looked somewhat carefully at the rest of the code for similar flaws. SCTP and DTLS seem a little more likely. Edited: tired, forgot to write "SRP" in the first sentence.