Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ad90b3ba7fc045f8e8acd6da5b77658d@smtp.hushmail.com>
Date: Wed, 9 Dec 2015 00:47:47 +0100
From: magnum <john.magnum@...hmail.com>
To: john-dev@...ts.openwall.com
Subject: Re: double free in ssh2john

On 2015-12-08 22:54, Hanno Böck wrote:
> There is a double free error in ssh2john if you run it against a file
> that contains two ssl certificate blocks.
>
> Just take a random certificate, add it twice to a file:
> cat test.crt test.crt > out.crt
>
> and run
> ssh2john out.crt
>
> Seems there is a loop that is freeing all openssl objects at the end of
> the loop and then reusing the same objects and freeing them for every
> iteration of the loop.

Thank you for reporting, I'll open an issue for it.

magnum

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.