<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib, branch OPENBSD_4_6</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_4_6</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_4_6'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2010-03-31T12:17:29+00:00</updated>
<entry>
<title>Security fix for CVE-2010-0740</title>
<updated>2010-03-31T12:17:29+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-03-31T12:17:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=48b786510a2e23cb712e96454a283cc7216d9070'/>
<id>urn:sha1:48b786510a2e23cb712e96454a283cc7216d9070</id>
<content type='text'>
"In TLS connections, certain incorrectly formatted records can cause an OpenSSL
client or server to crash due to a read attempt at NULL."

http://openssl.org/news/secadv_20100324.txt

ok djm@ sthen@
</content>
</entry>
<entry>
<title>MFC, original commit by djm@:</title>
<updated>2010-03-12T13:26:08+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-03-12T13:26:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e1d514d70c111ea04798fa6e97072ea06e0ae866'/>
<id>urn:sha1:e1d514d70c111ea04798fa6e97072ea06e0ae866</id>
<content type='text'>
---------------------------
cherrypick patch from OpenSSL 0.9.8m:

  *) Always check bn_wexpend() return values for failure.  (CVE-2009-3245)
     [Martin Olsson, Neel Mehta]

---------------------------

ok sthen@
</content>
</entry>
<entry>
<title>Pull Ben Lauries blind prefix injection fix for CVE-2009-3555 from</title>
<updated>2009-11-17T14:34:56+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2009-11-17T14:34:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=de2fb3aaad9c4aa5d5d324196d0e51de75946223'/>
<id>urn:sha1:de2fb3aaad9c4aa5d5d324196d0e51de75946223</id>
<content type='text'>
openssl 0.9.8l.

As suggested by markus@, for -stable the header change is being
restricted to a private file, so the minor version is not cranked here.

Discussed with markus, djm, deraadt.
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_4_6'.</title>
<updated>2009-06-25T14:33:52+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2009-06-25T14:33:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=dff7a49e263b7f35da41af95b2c037ed7cf6f71a'/>
<id>urn:sha1:dff7a49e263b7f35da41af95b2c037ed7cf6f71a</id>
<content type='text'>
</content>
</entry>
<entry>
<title>abs conforms c99 -&gt; imaxabs conforms c99.  ok millert@</title>
<updated>2009-06-21T00:33:10+00:00</updated>
<author>
<name>martynas</name>
<email></email>
</author>
<published>2009-06-21T00:33:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c2fd5f6b247d86a45d952c9b689af7c86ba86a46'/>
<id>urn:sha1:c2fd5f6b247d86a45d952c9b689af7c86ba86a46</id>
<content type='text'>
</content>
</entry>
<entry>
<title>quieten compiler by converting pointers to uintptr_t before truncating them</title>
<updated>2009-06-08T19:21:08+00:00</updated>
<author>
<name>deraadt</name>
<email></email>
</author>
<published>2009-06-08T19:21:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7da661713b58fcaf339fde465c90ead048d3745e'/>
<id>urn:sha1:7da661713b58fcaf339fde465c90ead048d3745e</id>
<content type='text'>
to u_int32_t to do integer math with (in a situation where that is legit)
ok otto millert
</content>
</entry>
<entry>
<title>compare and shift buffer against a fixed length not strlen derived values.</title>
<updated>2009-06-05T09:52:26+00:00</updated>
<author>
<name>pyr</name>
<email></email>
</author>
<published>2009-06-05T09:52:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9473bb6bbf2b4e61b9ebbe974edd44839206a598'/>
<id>urn:sha1:9473bb6bbf2b4e61b9ebbe974edd44839206a598</id>
<content type='text'>
ok otto@
</content>
</entry>
<entry>
<title>simplify the 'family' option parser and make it more evident what we're</title>
<updated>2009-06-04T21:38:29+00:00</updated>
<author>
<name>pyr</name>
<email></email>
</author>
<published>2009-06-04T21:38:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=67bdfcf045d3053a07637a70c9e1e9555375bc09'/>
<id>urn:sha1:67bdfcf045d3053a07637a70c9e1e9555375bc09</id>
<content type='text'>
now doing.

ok deraadt@
</content>
</entry>
<entry>
<title>Don't assume that we can overwrite strings in the environment.</title>
<updated>2009-06-04T20:39:13+00:00</updated>
<author>
<name>millert</name>
<email></email>
</author>
<published>2009-06-04T20:39:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=b77bc4fc41b396fdfad2c3601e64aa26f6c0ed7f'/>
<id>urn:sha1:b77bc4fc41b396fdfad2c3601e64aa26f6c0ed7f</id>
<content type='text'>
Someone may have passed a read-only string to putenv() (I'm looking
at you cron!).
</content>
</entry>
<entry>
<title>Add a resolv.conf option to specify the order in which getaddrinfo</title>
<updated>2009-06-04T18:06:35+00:00</updated>
<author>
<name>pyr</name>
<email></email>
</author>
<published>2009-06-04T18:06:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=27641c0c9895f7604965e9477480977868caec77'/>
<id>urn:sha1:27641c0c9895f7604965e9477480977868caec77</id>
<content type='text'>
PF_UNSPEC queries are made. While there change the default from inet6
first then inet4 to inet4 first then inet6, this prevents the many
people with IPv4 only connectivity from constantly trying to contact
IPv6 addresses, and also unbreaks many ports who don't use getaddrinfo
right.

ok deraadt@, plenty of cheering in the room wrt the idea, not loud
enough complaining from the v6 crowd.
</content>
</entry>
</feed>
