. The design is just plain wrong.
From what I understand about the bug (I have not seen the code) it soundslike data length informationarrived both directly and indirectly in the client message and that aconflict between them was notscrutinized.
No. The bug was that the keep alive protocol in SSL mandates the server to
echo arbitrary data back to the client. The bounds checks were wrong too,
but at that stage it really doesn't matter. The design is just plain wrong.
_______________________________________________
pro mailing list
pro@common-lisp.net
http://common-lisp.net/cgi-bin/mailman/listinfo/pro