RSAREF Buffer Overflow
Python writes "OpenBSD have issued a security
advisory
describing a buffer overflow problem in the RSA crypto reference
implementation.
RSA crypto is patented in the US (expiring Sept 20, 2000), and for
non-commercial use, RSA Inc. requires the use of their reference
implementation (called RSAREF2).
So not only are software patents a bad thing - they can even
force you into using a crypro reference implementation with
known security bugs..." It's worth noting that this is not just an OpenBSD issue. Anything that uses the RSA reference implementation will have the problem.
0 comments
No comments preserved for this story.