RSSAmplifier

The Fuzzing Project · Oct 15, 2016

Update on MatrixSSL miscalculation (CVE-2016-8671, incomplete fix for CVE-2016-6887)

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

I recently reported how I found various bugs in the bignum implementation of MatrixSSL , some of them leading to remotely exploitable vulnerabilities. One of the bugs was that the modular exponentiation function - pstm_exptmod() - produced wrong results for some inputs . This wasn't really fixed, but only worked around by restricting the allowed size of the modulus. Not surprisingly it is still…

Read on blog.fuzzing-project.org

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.