Dbase32 1.2
Milestone information
- Project:
- Dbase32
- Series:
- trunk
- Version:
- 1.2
- Released:
- Registrant:
- Jason Gerard DeRose
- Release registered:
- Active:
- No. Drivers cannot target bugs and blueprints to this milestone.
Activities
- Assigned to you:
- No blueprints or bugs assigned to you.
- Assignees:
- 1 Jason Gerard DeRose
- Blueprints:
- No blueprints are targeted to this milestone.
- Bugs:
- 1 Fix Released
Download files for this release
Release notes
* Mitigate vulnerability to timing attacks in `db32dec()` and `check_db32()` C implementations that could potentially be used against Dbase32 consumers that Dbase32-encode secret data or attacker controllable data that interacts with secret data; note that there are still know potential timing-attack issues, but Dbase32 1.2 is a big step in the right direction security-wise.
For more details, please see:
http://
Changelog
This release does not have a changelog.
0 blueprints and 1 bug targeted
Bug report | Importance | Assignee | Status | |||
---|---|---|---|---|---|---|
1359828 | #1359828 | Mitigate timing leakage in error handling | 2 Critical | Jason Gerard DeRose | 10 Fix Released |