The Fuzzing Project · Oct 15, 2016
Update on MatrixSSL miscalculation (CVE-2016-8671, incomplete fix for CVE-2016-6887)
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
I recently reported how I found various bugs in the bignum implementation of MatrixSSL , some of them leading to remotely exploitable vulnerabilities. One of the bugs was that the modular exponentiation function - pstm_exptmod() - produced wrong results for some inputs . This wasn't really fixed, but only worked around by restricting the allowed size of the modulus. Not surprisingly it is still…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.