<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib, branch OPENBSD_3_2</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_3_2</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_3_2'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2003-10-01T22:46:22+00:00</updated>
<entry>
<title>Pull patch from -current:</title>
<updated>2003-10-01T22:46:22+00:00</updated>
<author>
<name>brad</name>
<email></email>
</author>
<published>2003-10-01T22:46:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2090f88646016d40fe8f16635bd274711171e5d9'/>
<id>urn:sha1:2090f88646016d40fe8f16635bd274711171e5d9</id>
<content type='text'>
SECURITY FIX
Fixed by markus@
security fix from http://www.openssl.org/news/secadv_20030930.txt

ok markus@ deraadt@
</content>
</entry>
<entry>
<title>MFC:</title>
<updated>2003-08-03T02:29:29+00:00</updated>
<author>
<name>brad</name>
<email></email>
</author>
<published>2003-08-03T02:29:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c4a5e23a629462f7c5d45410243a6450fde919ee'/>
<id>urn:sha1:c4a5e23a629462f7c5d45410243a6450fde919ee</id>
<content type='text'>
Fix by millert@

Rename rootd to needslash and invert its value.  This fixes the check
for ENAMETOOLONG, though since we use strlcpy() and strlcat() this
is not a big deal.  Problem found by vincent@

ok deraadt@
</content>
</entry>
<entry>
<title>Errata #11 (markus):</title>
<updated>2003-03-19T23:39:13+00:00</updated>
<author>
<name>margarida</name>
<email></email>
</author>
<published>2003-03-19T23:39:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f1617cf3a6465e4bcee0aa9c5796426d1cbe5c3e'/>
<id>urn:sha1:f1617cf3a6465e4bcee0aa9c5796426d1cbe5c3e</id>
<content type='text'>
Fix for Klima-Pokorny-Rosa attack on RSA in SSL/TLS
</content>
</entry>
<entry>
<title>Errata #11 (markus):</title>
<updated>2003-03-19T01:18:21+00:00</updated>
<author>
<name>margarida</name>
<email></email>
</author>
<published>2003-03-19T01:18:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=955149d2c1094d65e72b4aad057026602d935717'/>
<id>urn:sha1:955149d2c1094d65e72b4aad057026602d935717</id>
<content type='text'>
Enforce blinding on RSA operations involving private keys.

millert@ markus@ ok
</content>
</entry>
<entry>
<title>Pull patch from current:</title>
<updated>2003-02-22T22:14:48+00:00</updated>
<author>
<name>margarida</name>
<email></email>
</author>
<published>2003-02-22T22:14:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=700eda6d2089d1107f8d3533246f55e9bc940421'/>
<id>urn:sha1:700eda6d2089d1107f8d3533246f55e9bc940421</id>
<content type='text'>
Fix by markus@

check for size &lt; 0 when allocating memory, from openssl (-r1.34)

markus@ deraadt@ ok
</content>
</entry>
<entry>
<title>Pull patch from current:</title>
<updated>2003-02-22T22:12:13+00:00</updated>
<author>
<name>margarida</name>
<email></email>
</author>
<published>2003-02-22T22:12:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=04ae3075fa0cc80f52dd9e034f60b1de03fb3839'/>
<id>urn:sha1:04ae3075fa0cc80f52dd9e034f60b1de03fb3839</id>
<content type='text'>
Fix by markus@
security fix from openssl 0.9.7a:

In ssl3_get_record (ssl/s3_pkt.c), minimize information leaked
via timing by performing a MAC computation even if incorrrect
block cipher padding has been found.  This is a countermeasure
against active attacks where the attacker has to distinguish
between bad padding and a MAC verification error. (CAN-2003-0078)

markus@ ok
</content>
</entry>
<entry>
<title>Apply http://www.isc.org/products/BIND/patches/bind4910.diff</title>
<updated>2002-11-14T23:50:10+00:00</updated>
<author>
<name>millert</name>
<email></email>
</author>
<published>2002-11-14T23:50:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e9a5dfe3c71ee8b6991f155c913551a5a9d68b5f'/>
<id>urn:sha1:e9a5dfe3c71ee8b6991f155c913551a5a9d68b5f</id>
<content type='text'>
Fixes bugs listed in http://www.isc.org/products/BIND/bind-security.html
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_3_2'.</title>
<updated>2002-09-26T11:41:24+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2002-09-26T11:41:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=26781b3d722ed1db43f641e4e7c862ae6bb1b83f'/>
<id>urn:sha1:26781b3d722ed1db43f641e4e7c862ae6bb1b83f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>do not install mdc2 man pages; markus ok</title>
<updated>2002-09-26T11:41:22+00:00</updated>
<author>
<name>deraadt</name>
<email></email>
</author>
<published>2002-09-26T11:41:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=af61e3f7dbe1fd8b363339d8ec5d6aec5f400ce3'/>
<id>urn:sha1:af61e3f7dbe1fd8b363339d8ec5d6aec5f400ce3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>remove MDC2; patents</title>
<updated>2002-09-26T11:39:50+00:00</updated>
<author>
<name>markus</name>
<email></email>
</author>
<published>2002-09-26T11:39:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=1ff7efb02515a78757c23473432f37ed75812fe3'/>
<id>urn:sha1:1ff7efb02515a78757c23473432f37ed75812fe3</id>
<content type='text'>
</content>
</entry>
</feed>
