Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The pandemic of incomplete OpenSSL error handling (jak-linux.org)
7 points by teddyh 86 days ago | hide | past | favorite | 1 comment


Recklessly discarding OpenSSL errors is really bad and could lead to security vulnerabilities.

Calling ERR_clear_error before operations is widely recommended: https://github.com/openssl/openssl/discussions/23025

which matches the blog author's point.

How widespread is this OpenSSL error discarding practice? It might explain a lot of security vulnerabilities.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: