Hi. I've been encoutering this issue on my OpenSSL-1.1.1 application.
Do you have any workaround? I found that SSL_SESSION list is corrupted
but I don't have any SSL_SESSSION related code in my app.

You can notice that symptom is same from the following backtrace:

/usr/local/bin/worker[0x509a21]
/usr/local/bin/worker(OPENSSL_LH_doall_arg+0x4f)[0x62e65f]
/usr/local/bin/worker(SSL_CTX_flush_sessions+0x57)[0x50abb7]
/usr/local/bin/worker(tls_finish_handshake+0x193)[0x520763]
/usr/local/bin/worker[0x5160c2]
/usr/local/bin/worker(async_start_func+0x2c)[0x55b58c]

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1847275

Title:
  stunnel4: "INTERNAL ERROR: Bad magic at ssl.c, line 117" - DoS
  vulnerability

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/stunnel4/+bug/1847275/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to