Skip to content
Snippets Groups Projects
  1. Apr 14, 2014
  2. Apr 13, 2014
    • Jan Včelák's avatar
      TSIG: fix possible weakness in signature checking · e796477d
      Jan Včelák authored
      Use binary comparison instead of string comparison for the received MAC.
      
      The transaction signature was checked only partially, if the MAC
      contained a zero byte. If this was the very first byte of the signature,
      the checking didn't happen at all. In addition, possible ASCII
      characters in the MAC were compared case insensitively.
      e796477d
  3. Apr 12, 2014
  4. Apr 11, 2014
  5. Apr 10, 2014
  6. Apr 09, 2014