bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#22202: 24.5; SECURITY ISSUE -- Emacs Server vulnerable to random num


From: Paul Eggert
Subject: bug#22202: 24.5; SECURITY ISSUE -- Emacs Server vulnerable to random number generator attack on Windows systems
Date: Sun, 17 Jan 2016 17:42:44 -0800
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1

Andreas Schwab discovered a problem with my patch in that GnuTLS wasn't initialized, and reverted the GnuTLS part of it. As I understand it, newer versions of GnuTLS initialize themselves when they are loaded and so do not run into the issue; I tested with GnuTLS 3.3.15, which I suppose is new enough. I attempted to fix this problem in the followup commit 130d512045aa376333b664d58c501b3884187592.

Andreas's commit also changed some unrelated style issues, which I reverted; that is merely a longrunning stylistic disagreement, and right now is not a good time to be changing style in code unrelated to fixes.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]