Bug report -- potential memory leak

Martin Vejnár Martin.Vejnar at avg.com
Sat Jun 20 09:58:19 UTC 2015


Hi,

affects all systems, happens at least in OpenSSL 1.0.2c.

In `crypto/cms/cms_smime.c`, the function `CMS_verify` will leak memory pointed to by `cms_certs` and `crls` variables if the call to `BIO_new_mem_buf` on line 374 fails.

Thanks,
--
Martin

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-bugs-mod/attachments/20150620/638e7c26/attachment.html>


More information about the openssl-bugs-mod mailing list