<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libssl, branch libressl-v2.1.9</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v2.1.9</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v2.1.9'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2015-12-04T04:22:24+00:00</updated>
<entry>
<title>Fix for OpenSSL CVE-2015-3195</title>
<updated>2015-12-04T04:22:24+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2015-12-04T04:22:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9d74b492cb913dd2f6ff73e839389649c588d06f'/>
<id>urn:sha1:9d74b492cb913dd2f6ff73e839389649c588d06f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>patch for OpenSSL CVE-2015-3194</title>
<updated>2015-12-04T04:15:54+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2015-12-04T04:15:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9ec6d4074b5f3899c59d4224b79f5138ea47ab78'/>
<id>urn:sha1:9ec6d4074b5f3899c59d4224b79f5138ea47ab78</id>
<content type='text'>
</content>
</entry>
<entry>
<title>pull up fixes for leak and overrun</title>
<updated>2015-10-15T02:23:26+00:00</updated>
<author>
<name>tedu</name>
<email></email>
</author>
<published>2015-10-15T02:23:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=1f0c7b9086ce1dc80bced5fa35412dcbdde99fa0'/>
<id>urn:sha1:1f0c7b9086ce1dc80bced5fa35412dcbdde99fa0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>MFC: Fix several defects from OpenSSL.</title>
<updated>2015-06-11T16:09:23+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-06-11T16:09:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7ef74dad52fbca9122cd668d868d85d0e0762a1a'/>
<id>urn:sha1:7ef74dad52fbca9122cd668d868d85d0e0762a1a</id>
<content type='text'>
These include:

CVE-2015-1788 - Malformed ECParameters causes infinite loop
CVE-2015-1789 - Exploitable out-of-bounds read in X509_cmp_time
CVE-2015-1792 - CMS verify infinite loop with unknown hash function
</content>
</entry>
<entry>
<title>Fix several crash causing defects from OpenSSL.</title>
<updated>2015-03-19T14:01:20+00:00</updated>
<author>
<name>tedu</name>
<email></email>
</author>
<published>2015-03-19T14:01:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5880eaad897594cd2996545010f7b301fa948230'/>
<id>urn:sha1:5880eaad897594cd2996545010f7b301fa948230</id>
<content type='text'>
These include:
CVE-2015-0209 - Use After Free following d2i_ECPrivatekey error
CVE-2015-0286 - Segmentation fault in ASN1_TYPE_cmp
CVE-2015-0287 - ASN.1 structure reuse memory corruption
CVE-2015-0288 - X509_to_X509_REQ NULL pointer deref
CVE-2015-0289 - PKCS7 NULL pointer dereferences

Several other issues did not apply or were already fixed.
Refer to https://www.openssl.org/news/secadv_20150319.txt

joint work with beck, doug, guenther, jsing, miod
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_5_7'.</title>
<updated>2015-03-08T16:48:49+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2015-03-08T16:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=03e0d0748934886665c3031cda5fdccf45f2fb8d'/>
<id>urn:sha1:03e0d0748934886665c3031cda5fdccf45f2fb8d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Reject DH keys sent by a server if they are considered too small; inspired</title>
<updated>2015-03-08T16:48:47+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2015-03-08T16:48:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=973703db67a8e73d70e63afa8f2cde19da09144d'/>
<id>urn:sha1:973703db67a8e73d70e63afa8f2cde19da09144d</id>
<content type='text'>
by a similar BoringSSL change, but raising the limit to 1024 bits.
ok jsing@ markus@ guenther@ deraadt@
</content>
</entry>
<entry>
<title>Fix a minor information leak that was introduced in t1_lib.c r1.71, whereby</title>
<updated>2015-03-02T13:43:09+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-03-02T13:43:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=45ee9e335c1b859ecec006aefb1a3c604a1c8d29'/>
<id>urn:sha1:45ee9e335c1b859ecec006aefb1a3c604a1c8d29</id>
<content type='text'>
an additional 28 bytes of .rodata (or .data) is provided to the network. In
most cases this is a non-issue since the memory content is already public.

Issue found and reported by Felix Groebert of the Google Security Team.

ok bcook@ beck@
</content>
</entry>
<entry>
<title>Fix CVE-2014-3570: properly calculate the square of a BIGNUM value.</title>
<updated>2015-02-25T15:39:49+00:00</updated>
<author>
<name>bcook</name>
<email></email>
</author>
<published>2015-02-25T15:39:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f3031aa7bff24911a8cae9bdd7cdcd88d8554f42'/>
<id>urn:sha1:f3031aa7bff24911a8cae9bdd7cdcd88d8554f42</id>
<content type='text'>
See https://www.openssl.org/news/secadv_20150108.txt for a more detailed
discussion.

Original OpenSSL patch here:
https://github.com/openssl/openssl/commit/a7a44ba55cb4f884c6bc9ceac90072dea38e66d0

The regression test is modified a little for KNF.
ok miod@
</content>
</entry>
<entry>
<title>Fix CVE-2015-0205: Do not accept client authentication with Diffie-Hellman</title>
<updated>2015-02-25T03:49:21+00:00</updated>
<author>
<name>bcook</name>
<email></email>
</author>
<published>2015-02-25T03:49:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=07a99d742112a2ad5f56da7d83e8519f21d605b9'/>
<id>urn:sha1:07a99d742112a2ad5f56da7d83e8519f21d605b9</id>
<content type='text'>
certificates without requiring a CertificateVerify message.

From OpenSSL commit:
https://github.com/openssl/openssl/commit/1421e0c584ae9120ca1b88098f13d6d2e90b83a3

Thanks to Karthikeyan Bhargavan for reporting this.
ok miod@
</content>
</entry>
</feed>
