Settings

Theme

OpenSSL Heartbeat Code

github.com

8 points by MIT_Hacker 12 years ago · 4 comments

Reader

syncerr 12 years ago

OpenSSL heartbeat bug patch (CVE-2014-0160):

https://github.com/openssl/openssl/commit/731f431497f463f3a2...

> A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server.

Previous discussion: https://news.ycombinator.com/item?id=7557825

askQi 12 years ago

Can someone explain which part of the code contains the bug and why it is a bug?

smtddr 12 years ago

https://github.com/openssl/openssl/commit/bd6941cfaa31ee8a3f...

Amelek is being a bit harsh or just plain wrong; I learned a few days ago that checking malloc's return value means almost nothing:

https://news.ycombinator.com/item?id=7541585

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection