summaryrefslogtreecommitdiff
path: root/changes
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2017-02-07 08:54:54 -0500
committerNick Mathewson <nickm@torproject.org>2017-02-07 08:54:54 -0500
commite6965f78b80e2b83367df05e204c97f5c0929a3c (patch)
treef833c83b2252897c672302a177411b851687f6f1 /changes
parent8936c50d83f3a90fb6bb3314b86f56f46d42d749 (diff)
parent6b37512dc76152926a16d93f2be52083cd5ae436 (diff)
downloadtor-e6965f78b80e2b83367df05e204c97f5c0929a3c.tar.gz
tor-e6965f78b80e2b83367df05e204c97f5c0929a3c.zip
Merge branch 'maint-0.2.5' into maint-0.2.6
Diffstat (limited to 'changes')
-rw-r--r--changes/rsa_init_bug7
1 files changed, 7 insertions, 0 deletions
diff --git a/changes/rsa_init_bug b/changes/rsa_init_bug
new file mode 100644
index 0000000000..6b5fb4f2f9
--- /dev/null
+++ b/changes/rsa_init_bug
@@ -0,0 +1,7 @@
+ o Major bugfixes (key management):
+ - If OpenSSL fails to generate an RSA key, do not retain a dangling pointer
+ to the previous (uninitialized) key value. The impact here should be
+ limited to a difficult-to-trigger crash, if OpenSSL is running an
+ engine that makes key generation failures possible, or if OpenSSL runs
+ out of memory. Fixes bug 19152; bugfix on 0.2.1.10-alpha. Found by
+ Yuan Jochen Kang, Suman Jana, and Baishakhi Ray.