<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libssl, branch OPENBSD_4_5</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_4_5</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_4_5'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2010-03-31T12:16:44+00:00</updated>
<entry>
<title>Security fix for CVE-2010-0740</title>
<updated>2010-03-31T12:16:44+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-03-31T12:16:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2ee55d26ee7a373bc8d7e0cd1e4532884ada8fa0'/>
<id>urn:sha1:2ee55d26ee7a373bc8d7e0cd1e4532884ada8fa0</id>
<content type='text'>
"In TLS connections, certain incorrectly formatted records can cause an OpenSSL
client or server to crash due to a read attempt at NULL."

http://openssl.org/news/secadv_20100324.txt

ok djm@ sthen@
</content>
</entry>
<entry>
<title>MFC, original commit by djm@:</title>
<updated>2010-03-12T13:26:41+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-03-12T13:26:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5876608ee68cc67de9b401842a171c25c54031c2'/>
<id>urn:sha1:5876608ee68cc67de9b401842a171c25c54031c2</id>
<content type='text'>
---------------------------
cherrypick patch from OpenSSL 0.9.8m:

  *) Always check bn_wexpend() return values for failure.  (CVE-2009-3245)
     [Martin Olsson, Neel Mehta]

---------------------------

ok sthen@
</content>
</entry>
<entry>
<title>Pull Ben Lauries blind prefix injection fix for CVE-2009-3555 from</title>
<updated>2009-11-17T14:34:41+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2009-11-17T14:34:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=990837b47cd7f41d299b338edf67d7771c204288'/>
<id>urn:sha1:990837b47cd7f41d299b338edf67d7771c204288</id>
<content type='text'>
openssl 0.9.8l.

As suggested by markus@, for -stable the header change is being
restricted to a private file, so the minor version is not cranked here.

Discussed with markus, djm, deraadt.
</content>
</entry>
<entry>
<title>MFC: fixes for OpenSSL ASN.1 invalid memory accesses (CVE-2009-0590 and</title>
<updated>2009-04-08T02:30:30+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-04-08T02:30:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=90917d997a66b5127abae66212a5ff788b40772b'/>
<id>urn:sha1:90917d997a66b5127abae66212a5ff788b40772b</id>
<content type='text'>
CVE-2009-0789).
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_4_5'.</title>
<updated>2009-02-18T15:24:57+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2009-02-18T15:24:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=ba772f784ace9fbd80465f5d6c91340dda14ca7e'/>
<id>urn:sha1:ba772f784ace9fbd80465f5d6c91340dda14ca7e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>missing ssl_sock_init() call in init_client() (used by</title>
<updated>2009-01-30T03:58:35+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-01-30T03:58:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=26ebb297ae136c0b5d1a4200bd9aeac375f078b6'/>
<id>urn:sha1:26ebb297ae136c0b5d1a4200bd9aeac375f078b6</id>
<content type='text'>
"openssl s_client"), fix an unlikely memory leak
</content>
</entry>
<entry>
<title>remove some gratuitous changes that do nothing other than inrease</title>
<updated>2009-01-30T03:56:05+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-01-30T03:56:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d7efac454212a21310500b6c840e8aa88706f48d'/>
<id>urn:sha1:d7efac454212a21310500b6c840e8aa88706f48d</id>
<content type='text'>
the size of the diff against openssl mainline
</content>
</entry>
<entry>
<title>convert a strdup (into a purpose-allocated buffer) in libcrypto to a</title>
<updated>2009-01-12T07:57:43+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-01-12T07:57:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=ee0b5fae7a537ef1e11c2882c414209b8f533e58'/>
<id>urn:sha1:ee0b5fae7a537ef1e11c2882c414209b8f533e58</id>
<content type='text'>
memcpy to avoid linker deprecation warnings; pointed out by dkrause@
</content>
</entry>
<entry>
<title>openssl-0.9.8j enables RFC3546 TLS extensions by default (e.g. the very</title>
<updated>2009-01-09T12:32:25+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-01-09T12:32:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2b0ae02b5f47fd5617da3480ef1ade14bc86155f'/>
<id>urn:sha1:2b0ae02b5f47fd5617da3480ef1ade14bc86155f</id>
<content type='text'>
useful "server name indication" that allows multihomed TLS server), so
remove the #define to disable it here
</content>
</entry>
<entry>
<title>adjust Makefile and crank major for openssl-0.9.8j</title>
<updated>2009-01-09T12:16:58+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2009-01-09T12:16:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=4e44f026fb3097b0f0c5c69d32f49ea214a4518f'/>
<id>urn:sha1:4e44f026fb3097b0f0c5c69d32f49ea214a4518f</id>
<content type='text'>
</content>
</entry>
</feed>
