OpenBSD Journal

LibreSSL 3.5.4 and 3.6.2 released

Contributed by rueda on from the initialize-my-revocation dept.

Hot on the heels of syspatches for OpenBSD 7.1 and 7.2, Brent Cook (bcook@) announced the release of versions 3.5.4 and 3.6.2 of LibreSSL:

We have released LibreSSL 3.5.4 and 3.6.2, which will be arriving in the
LibreSSL directory of your local OpenBSD mirror soon.

They include the following security fix:

  * A malicious certificate revocation list or timestamp response token
    would allow an attacker to read arbitrary memory.

LibreSSL 3.5.4 also includes the following reliability fix:

  * An uninitialized variable was used in ASN1_STRING_to_UTF8() to decide
    whether the no-op freezero(NULL, 0) should be called.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

(Comments are closed)


Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]