[openssl-dev] [openssl.org #4579] Bug - libcrypto.a null pointer dereference bug

Onur TAŞLIOĞLU via RT rt at openssl.org
Mon Jun 20 18:37:24 UTC 2016


1.0.2t version crashed in same place.

Operating System Version:
Distributor ID: Ubuntu
Description: Ubuntu 14.04.3 LTS
Release: 14.04
Codename: trusty
Linux 3.19.0-28-generic

OpenSSL Version : openssl-1.0.1t

Critical Function : X509_verify ();

And:

0x080e15ef in X509_verify (a=a at entry=0x0, r=r at entry=0x0) at x_all.c:75
75     if (X509_ALGOR_cmp(a->sig_alg, a->cert_info->signature))

Author: Onur TAŞLIOĞLU


2016-06-20 21:24 GMT+03:00 Onur TAŞLIOĞLU <onurtaslioglu1 at gmail.com>:

> Ok, i will try 1.0.2t version and open new ticket.
>
> Thanks.
>
> 2016-06-20 21:08 GMT+03:00 Rich Salz via RT <rt at openssl.org>:
>
>> 1.0.1 is end of life and only getting bugfixes now.
>> If you can reproduce this on 1.0.2 or master, please open a new ticket.
>> We also need more information, cannot reproduce this issue here.
>> Thanks. closing ticket.
>>
>> --
>> Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4579
>> Please log in as guest with password guest if prompted
>>
>>
>

-- 
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4579
Please log in as guest with password guest if prompted



More information about the openssl-dev mailing list