)]}'
{
  "commit": "e408c09bbf7c3057bda4b8d20bec1b3a7771c15b",
  "tree": "f1841a085ec97722ae1ad0d5014739bcd6c14fea",
  "parents": [
    "a449b47c7d8e20efc8cc524ed695a060b11ef889"
  ],
  "author": {
    "name": "Matt Caswell",
    "email": "matt@openssl.org",
    "time": "Fri Sep 09 10:08:45 2016 +0100"
  },
  "committer": {
    "name": "Matt Caswell",
    "email": "matt@openssl.org",
    "time": "Thu Sep 22 09:27:45 2016 +0100"
  },
  "message": "Fix OCSP Status Request extension unbounded memory growth\n\nA malicious client can send an excessively large OCSP Status Request\nextension. If that client continually requests renegotiation,\nsending a large OCSP Status Request extension each time, then there will\nbe unbounded memory growth on the server. This will eventually lead to a\nDenial Of Service attack through memory exhaustion. Servers with a\ndefault configuration are vulnerable even if they do not support OCSP.\nBuilds using the \"no-ocsp\" build time option are not affected.\n\nI have also checked other extensions to see if they suffer from a similar\nproblem but I could not find any other issues.\n\nCVE-2016-6304\n\nIssue reported by Shi Lei.\n\nReviewed-by: Rich Salz \u003crsalz@openssl.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "035353c33007e3a4f101ac2ea4c91b147649d823",
      "old_mode": 33188,
      "old_path": "ssl/t1_lib.c",
      "new_id": "d7ccea260d5f83495872376a48dd62560a7cec4c",
      "new_mode": 33188,
      "new_path": "ssl/t1_lib.c"
    }
  ]
}
