<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib, branch libressl-v2.1.10</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v2.1.10</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v2.1.10'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2016-01-27T02:11:36+00:00</updated>
<entry>
<title>deprecate SSL_OP_SINGLE_DH_USE</title>
<updated>2016-01-27T02:11:36+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2016-01-27T02:11:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=bc1a32b382ba2358d6f7b09fd14fd8923a14b7d6'/>
<id>urn:sha1:bc1a32b382ba2358d6f7b09fd14fd8923a14b7d6</id>
<content type='text'>
ok jsing@
</content>
</entry>
<entry>
<title>Fix for OpenSSL CVE-2015-3195</title>
<updated>2015-12-04T04:22:24+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2015-12-04T04:22:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9d74b492cb913dd2f6ff73e839389649c588d06f'/>
<id>urn:sha1:9d74b492cb913dd2f6ff73e839389649c588d06f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>patch for OpenSSL CVE-2015-3194</title>
<updated>2015-12-04T04:15:54+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2015-12-04T04:15:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9ec6d4074b5f3899c59d4224b79f5138ea47ab78'/>
<id>urn:sha1:9ec6d4074b5f3899c59d4224b79f5138ea47ab78</id>
<content type='text'>
</content>
</entry>
<entry>
<title>pull up fixes for leak and overrun</title>
<updated>2015-10-15T02:23:26+00:00</updated>
<author>
<name>tedu</name>
<email></email>
</author>
<published>2015-10-15T02:23:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=1f0c7b9086ce1dc80bced5fa35412dcbdde99fa0'/>
<id>urn:sha1:1f0c7b9086ce1dc80bced5fa35412dcbdde99fa0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>MFC: Fix several defects from OpenSSL.</title>
<updated>2015-06-11T16:09:23+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2015-06-11T16:09:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7ef74dad52fbca9122cd668d868d85d0e0762a1a'/>
<id>urn:sha1:7ef74dad52fbca9122cd668d868d85d0e0762a1a</id>
<content type='text'>
These include:

CVE-2015-1788 - Malformed ECParameters causes infinite loop
CVE-2015-1789 - Exploitable out-of-bounds read in X509_cmp_time
CVE-2015-1792 - CMS verify infinite loop with unknown hash function
</content>
</entry>
<entry>
<title>Fix several crash causing defects from OpenSSL.</title>
<updated>2015-03-19T14:01:20+00:00</updated>
<author>
<name>tedu</name>
<email></email>
</author>
<published>2015-03-19T14:01:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5880eaad897594cd2996545010f7b301fa948230'/>
<id>urn:sha1:5880eaad897594cd2996545010f7b301fa948230</id>
<content type='text'>
These include:
CVE-2015-0209 - Use After Free following d2i_ECPrivatekey error
CVE-2015-0286 - Segmentation fault in ASN1_TYPE_cmp
CVE-2015-0287 - ASN.1 structure reuse memory corruption
CVE-2015-0288 - X509_to_X509_REQ NULL pointer deref
CVE-2015-0289 - PKCS7 NULL pointer dereferences

Several other issues did not apply or were already fixed.
Refer to https://www.openssl.org/news/secadv_20150319.txt

joint work with beck, doug, guenther, jsing, miod
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_5_7'.</title>
<updated>2015-03-08T16:48:49+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2015-03-08T16:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=03e0d0748934886665c3031cda5fdccf45f2fb8d'/>
<id>urn:sha1:03e0d0748934886665c3031cda5fdccf45f2fb8d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Reject DH keys sent by a server if they are considered too small; inspired</title>
<updated>2015-03-08T16:48:47+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2015-03-08T16:48:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=973703db67a8e73d70e63afa8f2cde19da09144d'/>
<id>urn:sha1:973703db67a8e73d70e63afa8f2cde19da09144d</id>
<content type='text'>
by a similar BoringSSL change, but raising the limit to 1024 bits.
ok jsing@ markus@ guenther@ deraadt@
</content>
</entry>
<entry>
<title>Do not use sha512-parisc for now, as it is subtly bugged - passes the sha</title>
<updated>2015-03-05T20:35:28+00:00</updated>
<author>
<name>miod</name>
<email></email>
</author>
<published>2015-03-05T20:35:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=edab9f054cd9e7b7c2bb8b5683f63e8a6eaea617'/>
<id>urn:sha1:edab9f054cd9e7b7c2bb8b5683f63e8a6eaea617</id>
<content type='text'>
regress tests but causes tls ciphersuite using sha386 to fail; found the
hard way by henning@.

I can't see anything wrong in the generated assembly code yet, but building
a libcrypto with no assembler code but sha512_block_data_order() is enough
to trigger Henning's issue, so the bug lies there.

No ABI change; ok deraadt@
</content>
</entry>
<entry>
<title>Update comment to match code; Caspar Schutijser</title>
<updated>2015-03-02T21:41:08+00:00</updated>
<author>
<name>millert</name>
<email></email>
</author>
<published>2015-03-02T21:41:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f6e9eb23339296eec0a10399b584cbdf4948b62f'/>
<id>urn:sha1:f6e9eb23339296eec0a10399b584cbdf4948b62f</id>
<content type='text'>
</content>
</entry>
</feed>
