[openssl-dev] Testing CVE-2016-6309

Lysoněk Milan xlyson02 at stud.fit.vutbr.cz
Fri Apr 14 20:11:23 UTC 2017


On 06/04/17 00:25 Matt Caswell wrote:
> Can you reproduce it using the fuzz corpora added in commit 44f206aa9df,
> or by running the large message test introduced in 84d5549e69?
>
> Matt
>

Commit 44f206aa9df - All tests from this commit give me:

    OSError: [Errno 8] Exec format error

And I dont know, if its because my OS (Ubuntu 16.04 64bit) or I'm doing 
something wrong (I followed instructions from 
https://github.com/openssl/openssl/blob/master/fuzz/README.md )


Commit 84d5549e69 - It looks like this test reproduce it (I tried run 
tests with "./config","make" and then "make test")

    #   Failed test 'running sslapitest'
    #   at ../test/recipes/90-test_sslapi.t line 21.
    # Looks like you failed 1 test of 1.
    ../test/recipes/90-test_sslapi.t ........... Dubious, test returned
    1 (wstat 256, 0x100)
    Failed 1/1 subtests

It fails in 1.1.0a, but at 1.1.0b too, which is weird (also tried it at 
1.1.0e and here it was ok).


I'm not sure if I have done everything correctly in running these tests. 
I'm a newbie, so I apologize if I made any mistake.



Milan.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20170414/fe8c3481/attachment-0001.html>


More information about the openssl-dev mailing list