Subject: RSAREF2 buffer overflow?
To: None <>
From: Aaron J. Grier <>
List: tech-crypto
Date: 12/14/1999 13:15:51
apologies if this is the wrong list, but tech-security looks like it's
been dead for almost six months...

I know this doesn't apply to those outside the US [1], but the
NetBSD-specific section in the recent CERT advisory regarding buffer
overflows in RSAREF2 says basically "we advise recompiling things to not
use RSAREF2."  What about those of us who (for legal or other reasons)
don't have the option?

should I send-pr this?

[1] or even those inside the US who could care less about a certain
    software patent...

