The result was a terrible vulnerability, but it seems more of a case of spectacularly bad luck of everyone not spotting the issue.
The result was a terrible vulnerability, but it seems more of a case of spectacularly bad luck of everyone not spotting the issue.
Plus, the upstream OpenSSL code was invoking undefined behaviour. Hence the compiler could have validly made the exact same transformation as the Debian maintainer. At the time this felt academic: surely compilers can't be that mean! Since then I think undefined behaviour is better understood as a thing to avoid entirely.
Then, eight years later, Heartbleed was discovered. And we suddenly all realised how badly maintained OpenSSL was. In their defence, it was pretty much a volunteer job. Thankfully, subsequent funding has improved the situation.
Obligatory Dilbert https://imgur.com/uR4WuQ0 and XKCD: https://xkcd.com/221/