Dismissed
by @pyrox0 Activity log
- Created suggestion
- @pyrox0 ignored package netcat
- @pyrox0 dismissed
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 …
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.
References
-
http://packetstormsecurity.com/files/133998/Qualys-Security-Advisory-LibreSSL-L… x_refsource_MISCx_transferred
-
-
http://www.securityfocus.com/archive/1/archive/1/536692/100/0/threaded x_refsource_MISCx_transferred
-
-
http://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.1-relnotes.txt x_refsource_MISCx_transferred
Affected products
LibreSSL
- ==before 2.3.1
Matching in nixpkgs
pkgs.libressl
Free TLS/SSL implementation
pkgs.libressl_4_0
None
pkgs.libressl_4_1
Free TLS/SSL implementation
pkgs.libressl_4_2
Free TLS/SSL implementation
Package maintainers
-
@thoughtpolice Austin Seipp <aseipp@pobox.com>
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>