Bug#742240: libssl1.0.0: TLSv1_client_method()/SSL_Connect() heap overrun

2017-09-04 Thread Sebastian Andrzej Siewior
On 2014-03-21 02:04:11 [-0400], Brandon wrote: > When creating a client context with SSL_CTX_new(TLSv1_client_method()), > SSL_Connect() triggers a heap overrun with the following output from valgrind: Does this still occur as of 1.1.0f? > Thanks, > Brandon Sebastian

Bug#742240: libssl1.0.0: TLSv1_client_method()/SSL_Connect() heap overrun

2014-03-21 Thread Brandon
Package: libssl1.0.0 Version: 1.0.1e-2+deb7u4 Severity: normal Dear Maintainer, When creating a client context with SSL_CTX_new(TLSv1_client_method()), SSL_Connect() triggers a heap overrun with the following output from valgrind: ==24315== Thread 10: ==24315== Invalid write of size 4 ==24315==