New issue
Advanced search Search tips

Issue 736453 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Task



Sign in to add a comment

tlsdate: Patch Android fixes

Project Member Reported by jorgelo@chromium.org, Jun 23 2017

Issue description

Project Member

Comment 1 by sheriffbot@chromium.org, Jun 24 2017

Status: Assigned (was: Available)

Comment 2 by mmoroz@chromium.org, Jun 26 2017

Components: Internals>Network>Certificate
Labels: Security_Impact-Stable Security_Severity-Low
I'm speculatively assigning Low severity here, please change if needed.
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 18 2017

Labels: -M-61 M-62
Labels: -M-62 M-64
I looked at the commits, are these actually security bugs? 5a3de fixes compilation on MIPS64?
I don't think the various changes I made had security consequences, though the code was rather a mess. You would need them eventually if switching your OpenSSL 1.0.2 (due to be EOL at the end of 2019) to either BoringSSL or OpenSSL 1.1.0. Those being:

https://android.googlesource.com/platform/external/tlsdate/+/c339766a51d2db711171cb704e30b7ae916a987f
https://android.googlesource.com/platform/external/tlsdate/+/5a3de7f1137f650c5b4da38fcf3da3a00be905d2
Yeah those are the two that I suggested merging. We should just do it.
(Ah, hrm. For some reason your links have a %5E on them which is taking them to parent commits instead.)
Project Member

Comment 10 by sheriffbot@chromium.org, Mar 7 2018

Labels: -M-64 M-65
Cc: jorgelo@chromium.org
Labels: -Type-Bug-Security -Pri-2 -Security_Severity-Low -Security_Impact-Stable -M-65 Pri-3 Type-Task
Owner: ----
Status: Available (was: Assigned)
Keeping this open for the eventual OpenSSL uprev but this is not currently actionable, and also not a security bug.
Labels: Enterprise-Triaged

Sign in to add a comment