diff options
author | tb <> | 2020-12-08 15:10:03 +0000 |
---|---|---|
committer | tb <> | 2020-12-08 15:10:03 +0000 |
commit | 25128aa86b3c1fab0a730b15592a21b839ae5a03 (patch) | |
tree | ab578539bc4c69bc884b6e42f1cb7e99e6eb0216 /src/lib/libcrypto/sm3/sm3.c | |
parent | 3b56f0265346ac27187ab1c0aa41bc27260bea5b (diff) | |
download | openbsd-OPENBSD_6_7.tar.gz openbsd-OPENBSD_6_7.tar.bz2 openbsd-OPENBSD_6_7.zip |
Fix a NULL dereference in GENERAL_NAME_cmp()libressl-v3.1.5OPENBSD_6_7
Comparing two GENERAL_NAME structures containing an EDIPARTYNAME can lead
to a crash. This enables a denial of service attack for an attacker who can
control both sides of the comparison.
Issue reported to OpenSSL on Nov 9 by David Benjamin.
OpenSSL shared the information with us on Dec 1st.
Fix from Matt Caswell (OpenSSL) with a few small tweaks.
ok jsing
this is errata/6.7/031_asn1.patch.sig
Diffstat (limited to 'src/lib/libcrypto/sm3/sm3.c')
0 files changed, 0 insertions, 0 deletions