[openssl-dev] [openssl.org #4698] PEM parsing incorrect; whitespace in PEM crashes parser

Timothe Litt via RT rt at openssl.org
Wed Oct 5 12:02:54 UTC 2016


On 05-Oct-16 07:52, Salz, Rich via RT wrote:

> Well, it is a SHOULD not a MUST.  But point taken it could be (much) better :)
>
>
It's an important SHOULD.  Whitespace introduction happens in the wild.

This is the quote from the OpenXPKI folks:
> I just saw this today at a customer install that a user uploaded a
> PCSK10 request with extra newlines, anything based on Crypt::PKCS10 is
> happy with it but openssl crashes when it tries to sign.

See https://github.com/openxpki/openxpki/issues/437


-- 
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4698
Please log in as guest with password guest if prompted



More information about the openssl-dev mailing list