CVE-2016-2182.patch has broken BN_bn2dec

Bug #1626773 reported by Jeroen Ooms
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssl (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

My software which links to libcrypto stopped working on both Ubuntu 12.04 / 14.04 / 16.04 last week.

The problem is that BN_bn2dec returns NULL all the time (without setting an error message) even for valid input values. I think is a bug in CVE-2016-2182.patch.

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Can you provide some more details? USN-3087-1 was released just a few hours ago; if your software stopped working last week, it'd be worth investigating what packages changed last week, rather than today.

Thanks

Changed in openssl (Ubuntu):
status: New → Incomplete
Revision history for this message
Jeroen Ooms (jeroen) wrote :
summary: - CVE-2016-2182.patch has broken BN_bn2dec broken in 1.0.1
+ CVE-2016-2182.patch has broken BN_bn2dec
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Can you see if the regression fix we published today fixes your issue?

http://www.ubuntu.com/usn/usn-3087-2/

Revision history for this message
Jeroen Ooms (jeroen) wrote :

Yes, the problem seems to be fixed. Thank you.

Changed in openssl (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.