Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Bring back these two files to the 3.1 branch, after the latest libssl updateOPENBSD_3_1 | miod | 2003-05-25 | 4 | -0/+68 |
| | | | | | destroyed them by mistake. Sorry for the inconvenience, 3.1-STABLE should build again now. | ||||
* | Errata #025 (markus): | miod | 2003-03-19 | 1 | -14/+12 |
| | | | | Fix for Klima-Pokorny-Rosa attack on RSA in SSL/TLS | ||||
* | Errata #024 (markus): | miod | 2003-03-19 | 2 | -5/+31 |
| | | | | Enforce blinding on RSA operations involving private keys. | ||||
* | MFC (markus@): | miod | 2003-02-23 | 2 | -0/+12 |
| | | | | check for size < 0 when allocating memory, from openssl (-r1.34) | ||||
* | Errata 021: | miod | 2003-02-22 | 3 | -11/+48 |
| | | | | | | | | | | | | security fix from openssl 0.9.7a: In ssl3_get_record (ssl/s3_pkt.c), minimize information leaked via timing by performing a MAC computation even if incorrrect block cipher padding has been found. This is a countermeasure against active attacks where the attacker has to distinguish between bad padding and a MAC verification error. (CAN-2003-0078) adapted from a patch from Ryan W. Maple, via markus@ | ||||
* | Apply http://www.isc.org/products/BIND/patches/bind4910.diff | millert | 2002-11-14 | 1 | -22/+37 |
| | | | | Fixes bugs listed in http://www.isc.org/products/BIND/bind-security.html | ||||
* | Disable the engine stuff | jason | 2002-09-26 | 1 | -1/+2 |
| | |||||
* | Pull in patch from current: | jason | 2002-09-06 | 3 | -47/+77 |
| | | | | | Fix (itojun): allocate 64K recieve buffer for DNS responses. | ||||
* | Pull in patch from current: | jason | 2002-08-05 | 1 | -4/+5 |
| | | | | Better fixes from openssl cvs; from markus@ | ||||
* | Pull in patch from current: | jason | 2002-07-31 | 1 | -2/+2 |
| | | | | | Fix (deraadt): permit calloc(0, N) and calloc(N, 0) -- malloc(0) does the right thing | ||||
* | Pull in patch from current: | jason | 2002-07-30 | 16 | -7/+99 |
| | | | | | | Fix (markus), errata 013: apply patches from OpenSSL Security Advisory [30 July 2002], http://marc.theaimsgroup.com/?l=openssl-dev&m=102802395104110&w=2 | ||||
* | Pull in patch from current: | jason | 2002-07-30 | 1 | -1/+7 |
| | | | | | | Fix (deraadt): return failure if integer overflow happens. sigh; too people had to help get this right. | ||||
* | avoid remote buffer overrun on hostbuf[]. From: Joost Pol <joost@pine.nl> | millert | 2002-06-26 | 2 | -43/+33 |
| | | | | | | | | correct bad practice in the code - it uses two changing variables to manage buffer (buf and buflen). we eliminate buflen and use fixed point (ep) as the ending pointer. From: itojun this fix is critical. | ||||
* | This commit was manufactured by cvs2git to create branch 'OPENBSD_3_1'. | cvs2svn | 2002-03-12 | 554 | -134971/+0 |
| | |||||
* | Tack on MagniComp (BSD) license since this originally came from rdist. | millert | 2002-03-12 | 1 | -2/+30 |
| | |||||
* | check that we got the port before trying to listen | ericj | 2002-03-10 | 1 | -2/+2 |
| | | | | pr 2436; Alexander Yurchenko <grange@rt.mipt.ru> | ||||
* | Xr getifaddrs(3) and networking(4) in SEE ALSO section. | millert | 2002-03-07 | 1 | -1/+4 |
| | |||||
* | Replace SIOCGIFCONF-using NRL versions with KAME versions that use | millert | 2002-03-07 | 3 | -333/+201 |
| | | | | getifaddrs(3). Fixes problems on LP64 platforms. | ||||
* | add support for SOCKS4 with option -X socks_version, default is 5; ok ericj@ | markus | 2002-02-28 | 3 | -47/+86 |
| | |||||
* | skip sockaddr correctly if sa_len < sockaddr. from niklas | itojun | 2002-02-25 | 1 | -0/+3 |
| | |||||
* | Vax O1 workaround no longer needed. | hugh | 2002-02-23 | 1 | -2/+1 |
| | |||||
* | deraadt@ objects to the caveat remark, so remove it. | miod | 2002-02-23 | 1 | -11/+1 |
| | |||||
* | Slightly improve wording and punctuation. | miod | 2002-02-23 | 1 | -4/+4 |
| | |||||
* | Add a caveat section pointing out that people affecting the return value | miod | 2002-02-23 | 1 | -5/+13 |
| | | | | | | | | of getopt() to char variables instead of int lose on arches where char is unsigned by default. Clean the example by not pasting parts of <unistd.h> into it, and by not using atoi(3). | ||||
* | no more need to explicitly specify regress: _SUBDIRUSE targets anymore. | art | 2002-02-23 | 3 | -9/+3 |
| | | | | XXX - what about the install targets? | ||||
* | remove more old cruft | ericj | 2002-02-19 | 12 | -729/+0 |
| | |||||
* | man page fixes | ericj | 2002-02-19 | 1 | -8/+5 |
| | | | | from Kevin Steves <stevesk@pobox.com> | ||||
* | -Wall cleanup. | ericj | 2002-02-19 | 2 | -4/+8 |
| | | | | from Kevin Steves <stevesk@pobox.com> | ||||
* | remove old cruft | ericj | 2002-02-19 | 12 | -831/+0 |
| | |||||
* | We live in an ANSI C world. Remove lots of gratuitous #ifdef __STDC__ cruft. | millert | 2002-02-19 | 9 | -173/+15 |
| | |||||
* | Rename private err() function to dberr() to avoid collision with | millert | 2002-02-18 | 1 | -42/+49 |
| | | | | libc's err(). | ||||
* | clean | art | 2002-02-18 | 1 | -2/+3 |
| | |||||
* | tags cleanup. | art | 2002-02-18 | 2 | -2/+2 |
| | |||||
* | add longjmp | art | 2002-02-18 | 1 | -2/+2 |
| | |||||
* | Clean up. | art | 2002-02-18 | 2 | -2/+5 |
| | |||||
* | clean | art | 2002-02-18 | 2 | -7/+3 |
| | |||||
* | Return a failure if the test fails don't just fall out from main(). | art | 2002-02-18 | 1 | -2/+5 |
| | |||||
* | Manual cleanup of remaining userland __P use (excluding packages maintained ↵ | millert | 2002-02-17 | 11 | -54/+48 |
| | | | | outside the tree) | ||||
* | oops, add -U to usage | ericj | 2002-02-17 | 1 | -2/+2 |
| | |||||
* | add support for connecting too and listening on AF_UNIX sockets. | ericj | 2002-02-17 | 2 | -13/+111 |
| | | | | connect support from dave@arbor.net.. rest by me | ||||
* | fix pr#2091. patch applied. | ericj | 2002-02-17 | 1 | -2/+2 |
| | | | | | patch from Brian J. Kifiak <bk@rt.fm> should be looked at closer.. | ||||
* | Part one of userland __P removal. Done with a simple regexp with some minor ↵ | millert | 2002-02-16 | 33 | -145/+145 |
| | | | | hand editing to make comments line up correctly. Another pass is forthcoming that handles the cases that could not be done automatically. | ||||
* | + inf | pvalchev | 2002-02-16 | 1 | -2/+2 |
| | |||||
* | Simple test for isinf(3) and HUGE_VAL; ok art | pvalchev | 2002-02-16 | 2 | -0/+22 |
| | |||||
* | popen | art | 2002-02-16 | 1 | -2/+2 |
| | |||||
* | Tests for popen(3). From NetBSD. | art | 2002-02-16 | 2 | -0/+109 |
| | |||||
* | Remove references to nonexistent man pages. Ok theo, millert. | kjell | 2002-02-12 | 1 | -2/+1 |
| | |||||
* | but... on vax... des_enc.c requires -O1 | deraadt | 2002-02-10 | 1 | -1/+2 |
| | |||||
* | fix the history refs | mickey | 2002-01-24 | 1 | -2/+2 |
| | |||||
* | THREAD_UNLOCK() on error before returning; millert@ ok. | fgsch | 2002-01-23 | 1 | -1/+3 |
| |