LibreSSL 4.3.3 fixes OCSP responder authorization bypass
LibreSSL 4.3.3 is out as a maintenance update to the OpenBSD-developed TLS and cryptography library. The headline fix closes an OCSP responder authorization bypass in libtls and the ocspcheck utility, with additional corrections for DTLS, certificate verification and macOS/Windows builds.
- OCSP responder authorization bypass fixed in libtls and ocspcheck
- DTLS gets a corrected fragment size check and a handshake buffer limit
- Build support added for macOS Golden Gate 27.0 and MSVC ARM64 workaround
- CMake builds can now override TLS_DEFAULT_CA_FILE
Read next
Security