diff options
author | Nick Mathewson <nickm@torproject.org> | 2017-02-07 08:55:07 -0500 |
---|---|---|
committer | Nick Mathewson <nickm@torproject.org> | 2017-02-07 08:55:07 -0500 |
commit | 115cefdeeefd99f435948bfe42b1ce842019edfb (patch) | |
tree | 06b41270631e38e894fee7a8fb98da69317fca7f /changes | |
parent | eb72365554451f5e129169bb1216a9610f7ff183 (diff) | |
parent | e6965f78b80e2b83367df05e204c97f5c0929a3c (diff) | |
download | tor-115cefdeeefd99f435948bfe42b1ce842019edfb.tar.gz tor-115cefdeeefd99f435948bfe42b1ce842019edfb.zip |
Merge branch 'maint-0.2.6' into maint-0.2.7
Diffstat (limited to 'changes')
-rw-r--r-- | changes/rsa_init_bug | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/changes/rsa_init_bug b/changes/rsa_init_bug new file mode 100644 index 0000000000..6b5fb4f2f9 --- /dev/null +++ b/changes/rsa_init_bug @@ -0,0 +1,7 @@ + o Major bugfixes (key management): + - If OpenSSL fails to generate an RSA key, do not retain a dangling pointer + to the previous (uninitialized) key value. The impact here should be + limited to a difficult-to-trigger crash, if OpenSSL is running an + engine that makes key generation failures possible, or if OpenSSL runs + out of memory. Fixes bug 19152; bugfix on 0.2.1.10-alpha. Found by + Yuan Jochen Kang, Suman Jana, and Baishakhi Ray. |