Re: OpenSSL OCSP serious vulnerability

2016-09-22 Thread Jakob Bohm

On 22/09/2016 14:16, Richard Wang wrote:

OpenSSL OCSP Status Request extension unbounded memory growth (CVE-2016-6304)

http://security.360.cn/cve/CVE-2016-6304/index.html?from=timeline=0


Best Regards,

Richard



Let me take this opportunity to thank your parent company Qihoo 360 for
reporting this bug to the OpenSSL team, thus helping to protect us all.

Enjoy

Jakob
--
Jakob Bohm, CIO, Partner, WiseMo A/S.  https://www.wisemo.com
Transformervej 29, 2860 Søborg, Denmark.  Direct +45 31 13 16 10
This public discussion message is non-binding and may contain errors.
WiseMo - Remote Service Management for PCs, Phones and Embedded
___
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy


OpenSSL OCSP serious vulnerability

2016-09-22 Thread Richard Wang
OpenSSL OCSP Status Request extension unbounded memory growth (CVE-2016-6304)

http://security.360.cn/cve/CVE-2016-6304/index.html?from=timeline=0


Best Regards,

Richard
___
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy