|
|
Message-ID: <e8c3ae93-ea1d-42cb-aa77-20f71782f638@oracle.com>
Date: Fri, 16 Feb 2024 11:10:08 -0800
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: Re: Unbound: disclosure of CVE-2023-50387 and
CVE-2023-50868 DNSSEC validation vulnerabilities
On 2/13/24 14:34, Solar Designer wrote:
> It's not great that we're adding to a thread on Unbound, but since we
> already started...
Sorry, in hindsight I probably should have started a new thread.
For those who want more details on the CVE-2023-50387 flaw itself,
the researchers have now published their paper at
https://www.athene-center.de/en/keytrap (see the PDF link in the
"Technical Report" section).
--
-Alan Coopersmith- alan.coopersmith@...cle.com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.