<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib, branch OPENBSD_3_1</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_3_1</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_3_1'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2003-05-25T22:49:37+00:00</updated>
<entry>
<title>Bring back these two files to the 3.1 branch, after the latest libssl update</title>
<updated>2003-05-25T22:49:37+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2003-05-25T22:49:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e6f6c0f63e8b5db592667f610abc492cacadefca'/>
<id>urn:sha1:e6f6c0f63e8b5db592667f610abc492cacadefca</id>
<content type='text'>
destroyed them by mistake. Sorry for the inconvenience, 3.1-STABLE should
build again now.
</content>
</entry>
<entry>
<title>Errata #025 (markus):</title>
<updated>2003-03-19T23:25:41+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2003-03-19T23:25:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=64e4102ac6144c763a33eac43888cd0eb7e96d05'/>
<id>urn:sha1:64e4102ac6144c763a33eac43888cd0eb7e96d05</id>
<content type='text'>
Fix for Klima-Pokorny-Rosa attack on RSA in SSL/TLS
</content>
</entry>
<entry>
<title>Errata #024 (markus):</title>
<updated>2003-03-19T01:05:22+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2003-03-19T01:05:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3ca583df3c5813f2054dd9b42ad879000865c88d'/>
<id>urn:sha1:3ca583df3c5813f2054dd9b42ad879000865c88d</id>
<content type='text'>
Enforce blinding on RSA operations involving private keys.
</content>
</entry>
<entry>
<title>MFC (markus@):</title>
<updated>2003-02-23T16:16:02+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2003-02-23T16:16:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8d1a9d230c928e48c45a1800d762f52a13d614a0'/>
<id>urn:sha1:8d1a9d230c928e48c45a1800d762f52a13d614a0</id>
<content type='text'>
check for size &lt; 0 when allocating memory, from openssl (-r1.34)
</content>
</entry>
<entry>
<title>Errata 021:</title>
<updated>2003-02-22T17:46:50+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2003-02-22T17:46:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=87d7c154b9268b39059a87e45807e00030655fbf'/>
<id>urn:sha1:87d7c154b9268b39059a87e45807e00030655fbf</id>
<content type='text'>
security fix from openssl 0.9.7a:

In ssl3_get_record (ssl/s3_pkt.c), minimize information leaked
via timing by performing a MAC computation even if incorrrect
block cipher padding has been found.  This is a countermeasure
against active attacks where the attacker has to distinguish
between bad padding and a MAC verification error. (CAN-2003-0078)

adapted from a patch from Ryan W. Maple, via markus@
</content>
</entry>
<entry>
<title>Apply http://www.isc.org/products/BIND/patches/bind4910.diff</title>
<updated>2002-11-14T23:34:39+00:00</updated>
<author>
<name>millert</name>
<email></email>
</author>
<published>2002-11-14T23:34:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8e56586eb490b614a4b8859efc62af858f14f81c'/>
<id>urn:sha1:8e56586eb490b614a4b8859efc62af858f14f81c</id>
<content type='text'>
Fixes bugs listed in http://www.isc.org/products/BIND/bind-security.html
</content>
</entry>
<entry>
<title>Disable the engine stuff</title>
<updated>2002-09-26T22:08:25+00:00</updated>
<author>
<name>jason</name>
<email></email>
</author>
<published>2002-09-26T22:08:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a0be487a69b89fc315adf92fbed14db569c7fd40'/>
<id>urn:sha1:a0be487a69b89fc315adf92fbed14db569c7fd40</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Pull in patch from current:</title>
<updated>2002-09-06T05:46:51+00:00</updated>
<author>
<name>jason</name>
<email></email>
</author>
<published>2002-09-06T05:46:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=86f7d34adeb180c6f13c1d0e85e5b603b3ccc1c2'/>
<id>urn:sha1:86f7d34adeb180c6f13c1d0e85e5b603b3ccc1c2</id>
<content type='text'>
Fix (itojun):
allocate 64K recieve buffer for DNS responses.
</content>
</entry>
<entry>
<title>Pull in patch from current:</title>
<updated>2002-08-05T19:23:24+00:00</updated>
<author>
<name>jason</name>
<email></email>
</author>
<published>2002-08-05T19:23:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5383fa10b90fae75038aefab3a0ef8f9dc3fd835'/>
<id>urn:sha1:5383fa10b90fae75038aefab3a0ef8f9dc3fd835</id>
<content type='text'>
Better fixes from openssl cvs; from markus@
</content>
</entry>
<entry>
<title>Pull in patch from current:</title>
<updated>2002-07-31T16:40:07+00:00</updated>
<author>
<name>jason</name>
<email></email>
</author>
<published>2002-07-31T16:40:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c5c95eefd6134614711edfa693bb4aa5b5ee2a47'/>
<id>urn:sha1:c5c95eefd6134614711edfa693bb4aa5b5ee2a47</id>
<content type='text'>
Fix (deraadt):
permit calloc(0, N) and calloc(N, 0) -- malloc(0) does the right thing
</content>
</entry>
</feed>
