OpenBSD Errata: December 8th, 2020 (asn1)

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

OpenBSD Errata: December 8th, 2020 (asn1)

Theo Buehler-5
Errata patches for LibreSSL have been released for OpenBSD 6.7 and 6.8.

Malformed ASN.1 in a certificate revocation list or a timestamp
response token can lead to a NULL pointer dereference.

Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the respective
errata page:

  https://www.openbsd.org/errata67.html
  https://www.openbsd.org/errata68.html