Another leak: tls_new_client_session

Sam Hartman hartmans at mit.edu
Wed Mar 4 20:37:29 CET 2015


>>>>> "Alan" == Alan DeKok <aland at deployingradius.com> writes:

    Alan> On Mar 4, 2015, at 1:13 PM, Stefan Paetow <Stefan.Paetow at jisc.ac.uk> wrote:

    Alan>   Yes.  TBH, I have no idea how large the OpenSSL structures
    Alan> are, other than “OMG huge”.

Leaking the ssl structs with 2 client sessions was around 300k so if it
doesn't grow much beyond that, 356k could easily be plausible for no
leaks we care about.

--Sam



More information about the Freeradius-Devel mailing list