Skip to content

v0.10

@zhuizhuhaomeng zhuizhuhaomeng tagged this 07 Jun 12:03
Use CRYPTO_memcmp for the integrity-tag check to close a byte-by-byte timing oracle over an attacker-controlled plaintext prefix, and ngx_memcpy for the expiry timestamp to avoid an unaligned 64-bit read.
Assets 2
Loading