[openssl-dev] More POODLE issues

Richard Moore richmoore44 at gmail.com
Wed Dec 10 21:28:07 UTC 2014


Purely to give an independent answer - I'm not one of the openssl
developers and I've tested this. As expected the ssl3 implementation allows
any padding but the invalid padding is rejected with an alert when using
TLS. So as Matt has said, it's not a problem for openssl.

Cheers

Rich.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.opensslfoundation.net/pipermail/openssl-dev/attachments/20141210/2088e46f/attachment-0001.html>


More information about the openssl-dev mailing list