EmberCoin / Ember

Official Ember Blockchain
http://embercoin.io/
MIT License
25 stars 31 forks source link

Need new Windows build. Last uses openssl lib 1.0.1t which is vulnerable and is 32-bit only. #6

Closed aaashes closed 7 years ago

aaashes commented 7 years ago

Few info disclosures, overflows and DoS (boring...), see https://www.cvedetails.com/vulnerability-list/vendor_id-217/product_id-383/version_id-202288/Openssl-Openssl-1.0.1t.html, consider moving to 1.1.0f. We should also consider pushing out new PEs for both 32 and 64 over the weekend, with the second taking precedence over first.

EmberCoin commented 7 years ago

I am setting up building from LibreSSL version 2.5.5. I do not like OpenSSL at all.

aaashes commented 7 years ago

Originally avoided even mentioning other alternatives asides from our beloved trash fire. Promising to hear you're in favor of replacing. Its one of the more cleaner and concise libs out there for secure sockets, with mbedTLS taking second place.

EmberCoin commented 7 years ago

Fixed by #10 Leaving open until GUI build fixes.

EmberCoin commented 7 years ago

I had to revert to OpenSSL 1.0.2 in switching off windows architecture. I will try libressl again once we get building with mingw64 works (mingw32 is gross but at the time what they used)