android - spongy castle asn1 vulnerability -
openssl versions before april 2012 had vulnerability known asn1 bio vulnerability (http://www.openssl.org/news/secadv_20120419.txt).
using spongy castle on android solve our security needs, , wondering if spongy castle (or was) vulnerable well.
i did google search on subject, cannot find it.
does here know whether affects spongy castle @ all?
thanks!
bouncy castle and, extension, spongy castle not use openssl code asn.1 parsing. code developed in java, , afaik not borrow openssl. so, in theory, should not have same vulnerability. since related openssl-specific api's (bio's).
Comments
Post a Comment