Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, with updates to LibreSSL (2.1.7, 2.2.0) getting released today it looks like this has already been addressed. I can't find a decent link at the moment but according to an email I received a bit ago from owner-announce at openbsd.org 1788 is fixed in the above mentioned releases.

Fixes for the following issues are integrated into LibreSSL 2.1.7 and LibreSSL 2.2.0: - CVE-2015-1788 - Malformed ECParameters causes infinite loop - CVE-2015-1789 - Exploitable out-of-bounds read in X509_cmp_time - CVE-2015-1792 - CMS verify infinite loop with unknown hash function (this code is not enabled by default)

Edit - The updates included are mentioned here: https://github.com/libressl-portable/portable/blob/master/Ch...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: