IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: PublicKeyFile Format Security Considerations



> Implementors are cautioned to verify the correctness of the encoding/decoding
> routines used to save and read files in this format. A malfunctioning
> decoder used to read public-key data will most likely produce 
> invalid data with unknown cryptographic properties. In the worst
> case this cata could be vulnerable various forms of cryptographic attack.

I'm not sure that a cryptographic attack is the worst case.  Are we
sure that a malfunctioning decoder can't possibly be vulnerable to a
buffer overflow?






Home | Main Index | Thread Index | Old Index