Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: libressl_3_8

Found 2 matching suggestions

View:
Compact
Detailed
Untriaged
created 2 months ago Activity log
  • Created suggestion
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 …

Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.

Affected products

LibreSSL
  • ==before 2.3.1

Matching in nixpkgs

pkgs.netcat

Utility which reads and writes data across network connections — LibreSSL implementation

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 …

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

Affected products

LibreSSL
  • ==before 2.3.1

Matching in nixpkgs

pkgs.netcat

Utility which reads and writes data across network connections — LibreSSL implementation

Package maintainers