Browse Source
[IMPORTANT] An invalid Return value check in pkey_rsa_verifyrecover was discovered. When verification recovery fails for RSA keys an uninitialised buffer with an undefined length is returned instead of an error code. This could lead to an information leak. original advisory: http://www.openssl.org/news/secadv_20100601.txt CVE-2010-1633: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1633user/karasz/test/ecn
Christian Wiese
15 years ago
committed by
Christian Wiese
1 changed files with 2 additions and 2 deletions
Loading…
Reference in new issue