There appears to be a bit of confusion out there. To be clear:
1. The two bugs that were fixed in OpenSSL 1.1.1k [1] were introduced
well after the fork, so LibreSSL is not affected. OpenSSL have
kindly given us advance access to their fixes.
2. The bug fixed in LibreSSL 3.2.5 [2] is our own and entirely unrelated.
[1]: https://marc.info/?l=openssl-announce&m=161668124700970&w=2
[2]: https://marc.info/?l=openbsd-announce&m=161582456312832&w=2
No comments:
Post a Comment