|
Message-ID: <e8c3ae93-ea1d-42cb-aa77-20f71782f638@oracle.com> Date: Fri, 16 Feb 2024 11:10:08 -0800 From: Alan Coopersmith <alan.coopersmith@...cle.com> To: oss-security@...ts.openwall.com Subject: Re: Unbound: disclosure of CVE-2023-50387 and CVE-2023-50868 DNSSEC validation vulnerabilities On 2/13/24 14:34, Solar Designer wrote: > It's not great that we're adding to a thread on Unbound, but since we > already started... Sorry, in hindsight I probably should have started a new thread. For those who want more details on the CVE-2023-50387 flaw itself, the researchers have now published their paper at https://www.athene-center.de/en/keytrap (see the PDF link in the "Technical Report" section). -- -Alan Coopersmith- alan.coopersmith@...cle.com Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.