oss-sec mailing list archives

Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)


From: Demi Marie Obenour <demi () invisiblethingslab com>
Date: Tue, 1 Nov 2022 22:49:48 -0400

On Tue, Nov 01, 2022 at 09:52:59PM +0100, Erin Shepherd wrote:
LibreTLS does not track the OpenSSL API, so increasingly software does not build with it (it's not possible to 
support both LibreSSL and a supported version of OpenSSL without #ifdef hell)

Has software not from OpenBSD considered switching to LibreSSL outright?
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)
Invisible Things Lab

Attachment: signature.asc
Description:


Current thread: