OpenSSL Security Advisories – LibreSSL Largely Unaffected
undeadly.org
undeadly.org
* CVE-2015-0207 - Segmentation fault in DTLSv1_listen
LibreSSL is not vulnerable, but the fix was safe to merge.
http://marc.info/?l=openbsd-tech&m=142677928417277&w=2Every day, LibreSSL looks more attractive. I should take the time to learn to compile PHP to hook into it instead of openssl.
Is there some reason they're obscuring the fact that these are security vulns? Trying to keep their 'street cred' intact? (undeadly.org even uses quotes around "crash-inducing" in their announcement, so it seems obvious this is unusual language)