General

Profile

ikki

  • Registered on: 2015-10-25
  • Last connection: 2015-10-25

Issues

Activity

2015-10-25

22:50 Lighttpd Bug #2679 (Fixed): mod_secdownload md5 comparison vulnerable to timing attacks
In _mod_secure_download.c_ line 267, the following code is used for comparing the user-supplied MD5:
@
if (0 != ...

Also available in: Atom