| OpenSSL updates fix vulnerabilities |
| Source: H Security - Posted by Alex | ||
|
An uninitialised buffer in the EVP_PKEY_verify_recover() function in version 1.0.0 can be exploited to make an invalid RSA key appear to be valid. Since very few applications have used this recently-introduced function, the scope of this problem is limited. The OpenSSL developers say that pkeyutl is currently one of the only OpenSSL tools to access this function. [All of article]
Read this full article at H Security
Only registered users can write comments. Powered by AkoComment! |
||