A few more CVEs and we're at OpenSSL 1.1.1z, followed by v1.1.1.za, and it is going to break some package manager that in a certain locale orders versions as 1.1.1.za > 1.1.1z, and its users will be stuck on a vulnerable version.
OpenSSL Security Advisory [7th February 2023]
31–40 of 54 posts
Re: OpenSSL Security Advisory [7th February 2023]
#32Re: OpenSSL Security Advisory [7th February 2023]
#33Earlier quoted context omitted.
Why isn't it used more?
It's not 100% compatible with existing applications. IIRC Alpine Linux tried to switch and reverted back to openssl twice.
Re: OpenSSL Security Advisory [7th February 2023]
#34A reminder that LibreSSL exists and has a fraction of the problems OpenSSL does. https://www.libressl.org/
I love LibreSSL and what they represent, but neither LibreSSL nor BoringSSL target all platforms or compatibility with OpenSSL, which can be a bit of a challenge ... and I don't think LibreSSL is likely to have FIPS certification. At the AWS cryptography group, we've open-sourced our libcrypto - https://github.com/awslabs/aws-lc - which essentially tries to use the best from Google's BoringSSL, OpenSSL (from 1.1x , n…
It's surprisingly hard to get FIPS crypto in Golang on Windows.
Re: OpenSSL Security Advisory [7th February 2023]
#35Re: OpenSSL Security Advisory [7th February 2023]
#36A reminder that LibreSSL exists and has a fraction of the problems OpenSSL does. https://www.libressl.org/
https://github.com/rustls/rustls
Some thoughts on lessons learned from other projects/vulnerabilities:
Re: OpenSSL Security Advisory [7th February 2023]
#37One type error, one timing attack and six memory safety problems. Defect ratio checks out.
Re: OpenSSL Security Advisory [7th February 2023]
#38These pretty much all just look like the usual legacy crypto horror show bugs.
Re: OpenSSL Security Advisory [7th February 2023]
#39A reminder that LibreSSL exists and has a fraction of the problems OpenSSL does. https://www.libressl.org/
> A reminder that LibreSSL exists and has a fraction of the problems OpenSSL does. Ahem. Cough. Maybe I should leave this little link here for a patch published today ? https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x...
But this is just one round of patches, I have no further information or experience on/with LibreSSL or how the features compare. Just saying that one patch release does not mean either secure or insecure software.
Re: OpenSSL Security Advisory [7th February 2023]
#40 Alpine: OpenSSL 3.0.8 7 Feb 2023 (Library: OpenSSL 3.0.8 7 Feb 2023)
Void: OpenSSL 1.1.1t 7 Feb 2023