[18970] in cryptography@c2.net mail archive
Re: "ISAKMP" flaws?
daemon@ATHENA.MIT.EDU (Florian Weimer)
Thu Nov 17 09:29:07 2005
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: Florian Weimer <fw@deneb.enyo.de>
To: "Perry E. Metzger" <perry@piermont.com>
Cc: cryptography@metzdowd.com
Date: Thu, 17 Nov 2005 11:20:46 +0100
In-Reply-To: <8764qut02o.fsf@snark.piermont.com> (Perry E. Metzger's message
of "Tue, 15 Nov 2005 10:14:39 -0500")
* Perry E. Metzger:
> I haven't been following the IPSec mailing lists of late -- can anyone
> who knows details explain what the issue is?
These bugs have been uncovered by a PROTOS-style test suite. Such
test suites can only reveal missing checks for boundary conditions,
leading to out-of-bounds array accesses and things like that. In
other words, trivial implementation errors which can be easily avoided
using proper programming tools.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com