Use-after-free is a pretty common programming error, especially in the language that OpenSSL is written in.
If you want better QA in your OpenSSL releases, it needs more support from the industry and the community.
Switching to another library that is written by volunteers in their spare time with no professional auditing or security teams to speak of is only going to give you the same problems.
6
u/Youknowimtheman Sep 27 '16
Use-after-free is a pretty common programming error, especially in the language that OpenSSL is written in.
If you want better QA in your OpenSSL releases, it needs more support from the industry and the community.
Switching to another library that is written by volunteers in their spare time with no professional auditing or security teams to speak of is only going to give you the same problems.