Re: [openssl-dev] Testing CVE-2016-6309

2017-04-18 Thread Matt Caswell
On 14/04/17 21:11, Lysoněk Milan wrote: > > On 06/04/17 00:25 Matt Caswell wrote: >> Can you reproduce it using the fuzz corpora added in commit 44f206aa9df, >> or by running the large message test introduced in 84d5549e69? >> >> Matt >> > > Commit 44f206aa9df - All tests from this commit give

Re: [openssl-dev] Testing CVE-2016-6309

2017-04-14 Thread Lysoněk Milan
On 06/04/17 00:25 Matt Caswell wrote: Can you reproduce it using the fuzz corpora added in commit 44f206aa9df, or by running the large message test introduced in 84d5549e69? Matt Commit 44f206aa9df - All tests from this commit give me: OSError: [Errno 8] Exec format error And I dont

Re: [openssl-dev] Testing CVE-2016-6309

2017-04-05 Thread Matt Caswell
On 05/04/17 19:24, Lysoněk Milan wrote: > Hello, > I'd like to make test for CVE-2016-6309 > https://www.openssl.org/news/secadv/20160926.txt in tlsfuzzer. I tried > combining and sending different lengths (from small lengths to large) of > application data and padding, but I could not trigger

[openssl-dev] Testing CVE-2016-6309

2017-04-05 Thread Lysoněk Milan
Hello, I'd like to make test for CVE-2016-6309 https://www.openssl.org/news/secadv/20160926.txt in tlsfuzzer. I tried combining and sending different lengths (from small lengths to large) of application data and padding, but I could not trigger this issue on mentioned OpenSSL 1.1.0a. Is