Thanks for the answers, I am going to change BIO_write to BIO_printf in my product for openssl. And finally one question, NULL terminator is surely within the 128 bytes of buffer? regards, Gopi. -- View this message in context: http://openssl.6102.n7.nabble.com/CVE-2016-2180-tp67815p68395.html Sent from the OpenSSL - User mailing list archive at Nabble.com.