FreeBSD Security Advisory - OpenSSL Issues

Discussion in 'News Aggregator' started by Packet Storm, 8 Dec 2015.

  1. Packet Storm

    Packet Storm Guest

    FreeBSD Security Advisory - OpenSSL has had multiple vulnerabilities addressed. The signature verification routines will crash with a NULL pointer dereference if presented with an ASN.1 signature using the RSA PSS algorithm and absent mask generation function parameter. When presented with a malformed X509_ATTRIBUTE structure, OpenSSL will leak memory. If PSK identity hints are received by a multi-threaded client then the values are incorrectly updated in the parent SSL_CTX structure.

    Continue reading...
     

Share This Page

Loading...