[openssl.org #4699] Bug in OpenSSL 1.0.2j-fips 26 Sep 2016 or maybe affects all

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

[openssl.org #4699] Bug in OpenSSL 1.0.2j-fips 26 Sep 2016 or maybe affects all

Rich Salz via RT
It affects all 1.0.2 variants. I've a fix on github:
https://github.com/openssl/openssl/pull/1668

Cheers,
Richard

On Thu Oct 06 07:15:52 2016, [hidden email] wrote:

> Hi,
>
> While playing around with prime number generation I noticed that the
> following generates a core dump. I think this is definitely a bug.
>
> How to reproduce:
>
> $ openssl prime ''
> Segmentation fault (core dumped)
>
> I haven't included any strace output but this can be reproduced by you
> as well.
>
>
> Kind regards,


--
Richard Levitte
[hidden email]

--
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4699
Please log in as guest with password guest if prompted

--
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
Reply | Threaded
Open this post in threaded view
|

Re: [openssl.org #4699] Bug in OpenSSL 1.0.2j-fips 26 Sep 2016 or maybe affects all

Rich Salz via RT
Hi Richard,

Just saw the patch. Thanks for the quick response.

Valentin

On 10/06/2016 09:37 AM, Richard Levitte via RT wrote:

> It affects all 1.0.2 variants. I've a fix on github:
> https://github.com/openssl/openssl/pull/1668
>
> Cheers,
> Richard
>
> On Thu Oct 06 07:15:52 2016, [hidden email] wrote:
>> Hi,
>>
>> While playing around with prime number generation I noticed that the
>> following generates a core dump. I think this is definitely a bug.
>>
>> How to reproduce:
>>
>> $ openssl prime ''
>> Segmentation fault (core dumped)
>>
>> I haven't included any strace output but this can be reproduced by you
>> as well.
>>
>>
>> Kind regards,
>
>
> --
> Richard Levitte
> [hidden email]
>
--

Valentin Bajrami
Kapteyn Astronomical Institute
University of Groningen
Postbus 800
NL-9700 AV Groningen
The Netherlands

Phone:    +31-(0)50-3634068


--
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4699
Please log in as guest with password guest if prompted


--
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

signature.asc (1K) Download Attachment