aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRichard Levitte <levitte@openssl.org>2002-11-21 22:39:08 +0000
committerRichard Levitte <levitte@openssl.org>2002-11-21 22:39:08 +0000
commit364ff369d15aebe41088b61b97304c391e97480b (patch)
treedc5c82ecfcd5a4718a720aedac089639132c6a47
parent8a09b3866a9621210b80106b7512da710b0e17ce (diff)
downloadopenssl-364ff369d15aebe41088b61b97304c391e97480b.tar.gz
Mention a current showstopper
-rw-r--r--STATUS14
1 files changed, 13 insertions, 1 deletions
diff --git a/STATUS b/STATUS
index b15f1493dc..0d7707d0b6 100644
--- a/STATUS
+++ b/STATUS
@@ -1,6 +1,6 @@
OpenSSL STATUS Last modified at
- ______________ $Date: 2002/11/19 11:52:24 $
+ ______________ $Date: 2002/11/21 22:39:08 $
DEVELOPMENT STATE
@@ -33,6 +33,18 @@
o BN_mod_mul verification fails for mips3-sgi-irix
unless configured with no-asm
+ o [2002-11-21]
+ PR 343 mentions that scrubbing memory with 'memset(ptr, 0, n)' may
+ be optimized away in modern compilers. This is definitely not good
+ and needs to be fixed immediately. The formula to use is presented
+ in:
+
+ http://online.securityfocus.com/archive/82/297918/2002-10-27/2002-11-02/0
+
+ The problem report that mentions this is:
+
+ https://www.aet.TU-Cottbus.DE/rt2/Ticket/Display.html?id=343
+
AVAILABLE PATCHES
o