<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto, branch libressl-v2.1.10</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v2.1.10</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v2.1.10'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2015-03-08T16:48:49+00:00</updated>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_5_7'.</title>
<updated>2015-03-08T16:48:49+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2015-03-08T16:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=03e0d0748934886665c3031cda5fdccf45f2fb8d'/>
<id>urn:sha1:03e0d0748934886665c3031cda5fdccf45f2fb8d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Do not use sha512-parisc for now, as it is subtly bugged - passes the sha</title>
<updated>2015-03-05T20:35:28+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2015-03-05T20:35:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=edab9f054cd9e7b7c2bb8b5683f63e8a6eaea617'/>
<id>urn:sha1:edab9f054cd9e7b7c2bb8b5683f63e8a6eaea617</id>
<content type='text'>
regress tests but causes tls ciphersuite using sha386 to fail; found the
hard way by henning@.

I can't see anything wrong in the generated assembly code yet, but building
a libcrypto with no assembler code but sha512_block_data_order() is enough
to trigger Henning's issue, so the bug lies there.

No ABI change; ok deraadt@
</content>
</entry>
<entry>
<title>Fix CVE-2014-3570: properly calculate the square of a BIGNUM value.</title>
<updated>2015-02-25T15:39:49+00:00</updated>
<author>
<name>bcook</name>
<email></email>
</author>
<published>2015-02-25T15:39:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f3031aa7bff24911a8cae9bdd7cdcd88d8554f42'/>
<id>urn:sha1:f3031aa7bff24911a8cae9bdd7cdcd88d8554f42</id>
<content type='text'>
See https://www.openssl.org/news/secadv_20150108.txt for a more detailed
discussion.

Original OpenSSL patch here:
https://github.com/openssl/openssl/commit/a7a44ba55cb4f884c6bc9ceac90072dea38e66d0

The regression test is modified a little for KNF.
ok miod@
</content>
</entry>
<entry>
<title>fourth batch of perlpod(1) to mdoc(7) conversion</title>
<updated>2015-02-23T17:43:24+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2015-02-23T17:43:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3fed19a0557c5cc4db5053d380747aa1615cb201'/>
<id>urn:sha1:3fed19a0557c5cc4db5053d380747aa1615cb201</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Bump libcrypto and libssl majors, due to various recent churn.</title>
<updated>2015-02-22T16:03:06+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-02-22T16:03:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=bb820e160520888599d0966ac5d4a5270c855a23'/>
<id>urn:sha1:bb820e160520888599d0966ac5d4a5270c855a23</id>
<content type='text'>
Discussed with/requested by deraadt@ at the conclusion of s2k15.
</content>
</entry>
<entry>
<title>Remove IMPLEMENT_STACK_OF noops.</title>
<updated>2015-02-22T15:19:56+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-02-22T15:19:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3fa12a5d03a942018ff0c53594eedf9f2f1adb1c'/>
<id>urn:sha1:3fa12a5d03a942018ff0c53594eedf9f2f1adb1c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>If BN_rand() or BN_pseudo_rand() are called with a NULL rnd argument,</title>
<updated>2015-02-19T06:10:29+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-02-19T06:10:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=62ebecd0e093eb1e8a47512de67da5c951069913'/>
<id>urn:sha1:62ebecd0e093eb1e8a47512de67da5c951069913</id>
<content type='text'>
BN_bin2bn() will helpfully allocate a BN which is then leaked. Avoid this
by explicitly checking for NULL at the start of the bnrand() function.

Fixes Coverity ID 78831.

ok miod@
</content>
</entry>
<entry>
<title>Memory leak in error path. Coverity CID 78822.</title>
<updated>2015-02-17T05:14:38+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2015-02-17T05:14:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8d9d64b562cdb05c559dcc6168d8116ae5f085a5'/>
<id>urn:sha1:8d9d64b562cdb05c559dcc6168d8116ae5f085a5</id>
<content type='text'>
ok doug@
</content>
</entry>
<entry>
<title>third batch of perlpod(1) to mdoc(7) conversion</title>
<updated>2015-02-16T16:42:14+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2015-02-16T16:42:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=536268edf284379599d2db025c14989146460a7b'/>
<id>urn:sha1:536268edf284379599d2db025c14989146460a7b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Avoid calling BN_CTX_end() on a context that wasn't started.</title>
<updated>2015-02-15T22:29:02+00:00</updated>
<author>
<name>doug</name>
<email></email>
</author>
<published>2015-02-15T22:29:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=191c62e76a1c0617acb040a77924d270b58dcd9b'/>
<id>urn:sha1:191c62e76a1c0617acb040a77924d270b58dcd9b</id>
<content type='text'>
In dsa_builtin_paramgen(), if BN_MONT_CTX_new() fails, the BN_CTX_new()
call above it will have allocated a ctx without calling BN_CTX_start() on
it.  The error handling calls BN_CTX_end() when ctx is allocated.

Move the BN_MONT_CTX_new() call up so it will fail first without splitting
up the BN_CTX_new() and BN_CTX_start().

tweak + ok miod@, ok bcook@
</content>
</entry>
</feed>
