Skip to content

Check that unauthenticated plaintext is not leaked from OpenSSL #70

@Demi-Marie

Description

@Demi-Marie

If it is leaked, it is a security vulnerability. The entire plaintext must be buffered (either in memory, or in an anonymous and/or inaccessible temporary file) until the authentication tag can be checked.

Metadata

Metadata

Assignees

Labels

securityPull requests that address a security vulnerability

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions