Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <e8c3ae93-ea1d-42cb-aa77-20f71782f638@oracle.com>
Date: Fri, 16 Feb 2024 11:10:08 -0800
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: Re: Unbound: disclosure of CVE-2023-50387 and
 CVE-2023-50868 DNSSEC validation vulnerabilities

On 2/13/24 14:34, Solar Designer wrote:
> It's not great that we're adding to a thread on Unbound, but since we
> already started...

Sorry, in hindsight I probably should have started a new thread.

For those who want more details on the CVE-2023-50387 flaw itself,
the researchers have now published their paper at
https://www.athene-center.de/en/keytrap (see the PDF link in the
"Technical Report" section).

-- 
         -Alan Coopersmith-                 alan.coopersmith@...cle.com
          Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.