logo
Dates

Author


Conferences

Tags

Sort by:  

Authors: Dan Murphy, Frank Catucci
2023-02-16

tldr - powered by Generative AI

The presentation discusses a vulnerability in OpenSSL 3.0 that requires a specific set of circumstances to exploit, limiting its impact. The speaker emphasizes the importance of exploring and testing vulnerabilities to determine their actual risk.
  • The vulnerability requires a valid client certificate and occurs during the certificate handshake process
  • The affected code is a narrow window in OpenSSL 3.0, limiting the number of potential targets
  • The exploit requires a specific alignment of memory, making it difficult to execute
  • The speaker encourages a spirit of exploration and experimentation to determine the actual risk of vulnerabilities