<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libssl, branch OPENBSD_4_7</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_4_7</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_4_7'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2011-02-11T03:23:39+00:00</updated>
<entry>
<title>MFC:</title>
<updated>2011-02-11T03:23:39+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2011-02-11T03:23:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=de026953401bceeb507b84983e244639462d6598'/>
<id>urn:sha1:de026953401bceeb507b84983e244639462d6598</id>
<content type='text'>
----------------------------
revision 1.8
date: 2011/02/10 22:40:27;  author: djm;  state: Exp;  lines: +7 -1
fix for CVE-2011-0014 "OCSP stapling vulnerability";
ok markus@ jasper@ miod@

AFAIK nothing in base uses this, though apache2 from ports may be affected.
----------------------------
</content>
</entry>
<entry>
<title>Security fix for CVE-2010-4180 as mentioned in http://www.openssl.org/news/secadv_20101202.txt.</title>
<updated>2010-12-15T09:44:25+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-12-15T09:44:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e6411b47d6dcb44d9016266fae15f1292dfbd319'/>
<id>urn:sha1:e6411b47d6dcb44d9016266fae15f1292dfbd319</id>
<content type='text'>
where clients could modify the stored session
cache ciphersuite and in some cases even downgrade the suite to weaker ones.

This code is not enabled by default.

ok djm@
</content>
</entry>
<entry>
<title>- Apply security fix for CVE-2010-3864.</title>
<updated>2010-11-17T19:14:22+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-11-17T19:14:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=63a39dcec5af72c8e5548c4ab6e63f53ea446965'/>
<id>urn:sha1:63a39dcec5af72c8e5548c4ab6e63f53ea446965</id>
<content type='text'>
ok djm@ deraadt@
</content>
</entry>
<entry>
<title>ecurity fix for CVE-2010-0740</title>
<updated>2010-03-31T12:17:41+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-03-31T12:17:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=85441e218187c663da9c679f474a7160c85ee3f2'/>
<id>urn:sha1:85441e218187c663da9c679f474a7160c85ee3f2</id>
<content type='text'>
"In TLS connections, certain incorrectly formatted records can cause an OpenSSL
client or server to crash due to a read attempt at NULL."

http://openssl.org/news/secadv_20100324.txt

ok djm@ sthen@
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_4_7'.</title>
<updated>2010-03-10T20:46:18+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2010-03-10T20:46:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=b1588b57c8d7dac5211d733762cf8d4cd26aa459'/>
<id>urn:sha1:b1588b57c8d7dac5211d733762cf8d4cd26aa459</id>
<content type='text'>
</content>
</entry>
<entry>
<title>cherrypick patch from OpenSSL 0.9.8m:</title>
<updated>2010-03-04T11:02:42+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2010-03-04T11:02:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9f75721dec306b453d31851a26bad908e9605c4f'/>
<id>urn:sha1:9f75721dec306b453d31851a26bad908e9605c4f</id>
<content type='text'>
  *) Always check bn_wexpend() return values for failure.  (CVE-2009-3245)
     [Martin Olsson, Neel Mehta]
</content>
</entry>
<entry>
<title>Use MACHINE_CPU instead of MACHINE_ARCH to pick the correct machine dependent</title>
<updated>2010-02-03T20:49:00+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2010-02-03T20:49:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=aaa0cabd6a83ca6edba4b6122b65033db1337306'/>
<id>urn:sha1:aaa0cabd6a83ca6edba4b6122b65033db1337306</id>
<content type='text'>
files or directories when applicable.
The inspiration and name of MACHINE_CPU come from NetBSD, although the way to
provide it to Makefiles is completely different.
ok kettenis@
</content>
</entry>
<entry>
<title>add a fix from OpenSSL CVS for SA38200.</title>
<updated>2010-01-31T21:10:57+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-01-31T21:10:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=6007738228ce1f7b878db03c3e504020350a7e30'/>
<id>urn:sha1:6007738228ce1f7b878db03c3e504020350a7e30</id>
<content type='text'>
"Modify compression code so it avoids using ex_data free functions.
This stops applications that call CRYPTO_free_all_ex_data()
prematurely leaking memory."

looks ok to markus@
</content>
</entry>
<entry>
<title>new ipsca root.</title>
<updated>2009-12-31T07:13:15+00:00</updated>
<author>
<name>dlg</name>
<email></email>
</author>
<published>2009-12-31T07:13:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2b56f982cbba39b8740b0a4e07047b813c77197c'/>
<id>urn:sha1:2b56f982cbba39b8740b0a4e07047b813c77197c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>ipsca has expired</title>
<updated>2009-12-31T07:06:29+00:00</updated>
<author>
<name>dlg</name>
<email></email>
</author>
<published>2009-12-31T07:06:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f1ee178592ebcf18d85457f83d41dff80160be5d'/>
<id>urn:sha1:f1ee178592ebcf18d85457f83d41dff80160be5d</id>
<content type='text'>
</content>
</entry>
</feed>
