summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Bring back these two files to the 3.1 branch, after the latest libssl updateOPENBSD_3_1miod2003-05-254-0/+68
| | | | | destroyed them by mistake. Sorry for the inconvenience, 3.1-STABLE should build again now.
* Errata #025 (markus):miod2003-03-191-14/+12
| | | | Fix for Klima-Pokorny-Rosa attack on RSA in SSL/TLS
* Errata #024 (markus):miod2003-03-192-5/+31
| | | | Enforce blinding on RSA operations involving private keys.
* MFC (markus@):miod2003-02-232-0/+12
| | | | check for size < 0 when allocating memory, from openssl (-r1.34)
* Errata 021:miod2003-02-223-11/+48
| | | | | | | | | | | | security fix from openssl 0.9.7a: In ssl3_get_record (ssl/s3_pkt.c), minimize information leaked via timing by performing a MAC computation even if incorrrect block cipher padding has been found. This is a countermeasure against active attacks where the attacker has to distinguish between bad padding and a MAC verification error. (CAN-2003-0078) adapted from a patch from Ryan W. Maple, via markus@
* Apply http://www.isc.org/products/BIND/patches/bind4910.diffmillert2002-11-141-22/+37
| | | | Fixes bugs listed in http://www.isc.org/products/BIND/bind-security.html
* Disable the engine stuffjason2002-09-261-1/+2
|
* Pull in patch from current:jason2002-09-063-47/+77
| | | | | Fix (itojun): allocate 64K recieve buffer for DNS responses.
* Pull in patch from current:jason2002-08-051-4/+5
| | | | Better fixes from openssl cvs; from markus@
* Pull in patch from current:jason2002-07-311-2/+2
| | | | | Fix (deraadt): permit calloc(0, N) and calloc(N, 0) -- malloc(0) does the right thing
* Pull in patch from current:jason2002-07-3016-7/+99
| | | | | | Fix (markus), errata 013: apply patches from OpenSSL Security Advisory [30 July 2002], http://marc.theaimsgroup.com/?l=openssl-dev&m=102802395104110&w=2
* Pull in patch from current:jason2002-07-301-1/+7
| | | | | | Fix (deraadt): return failure if integer overflow happens. sigh; too people had to help get this right.
* avoid remote buffer overrun on hostbuf[]. From: Joost Pol <joost@pine.nl>millert2002-06-262-43/+33
| | | | | | | | correct bad practice in the code - it uses two changing variables to manage buffer (buf and buflen). we eliminate buflen and use fixed point (ep) as the ending pointer. From: itojun this fix is critical.
* This commit was manufactured by cvs2git to create branch 'OPENBSD_3_1'.cvs2svn2002-03-12554-134971/+0
|
* Tack on MagniComp (BSD) license since this originally came from rdist.millert2002-03-121-2/+30
|
* check that we got the port before trying to listenericj2002-03-101-2/+2
| | | | pr 2436; Alexander Yurchenko <grange@rt.mipt.ru>
* Xr getifaddrs(3) and networking(4) in SEE ALSO section.millert2002-03-071-1/+4
|
* Replace SIOCGIFCONF-using NRL versions with KAME versions that usemillert2002-03-073-333/+201
| | | | getifaddrs(3). Fixes problems on LP64 platforms.
* add support for SOCKS4 with option -X socks_version, default is 5; ok ericj@markus2002-02-283-47/+86
|
* skip sockaddr correctly if sa_len < sockaddr. from niklasitojun2002-02-251-0/+3
|
* Vax O1 workaround no longer needed.hugh2002-02-231-2/+1
|
* deraadt@ objects to the caveat remark, so remove it.miod2002-02-231-11/+1
|
* Slightly improve wording and punctuation.miod2002-02-231-4/+4
|
* Add a caveat section pointing out that people affecting the return valuemiod2002-02-231-5/+13
| | | | | | | | of getopt() to char variables instead of int lose on arches where char is unsigned by default. Clean the example by not pasting parts of <unistd.h> into it, and by not using atoi(3).
* no more need to explicitly specify regress: _SUBDIRUSE targets anymore.art2002-02-233-9/+3
| | | | XXX - what about the install targets?
* remove more old cruftericj2002-02-1912-729/+0
|
* man page fixesericj2002-02-191-8/+5
| | | | from Kevin Steves <stevesk@pobox.com>
* -Wall cleanup.ericj2002-02-192-4/+8
| | | | from Kevin Steves <stevesk@pobox.com>
* remove old cruftericj2002-02-1912-831/+0
|
* We live in an ANSI C world. Remove lots of gratuitous #ifdef __STDC__ cruft.millert2002-02-199-173/+15
|
* Rename private err() function to dberr() to avoid collision withmillert2002-02-181-42/+49
| | | | libc's err().
* cleanart2002-02-181-2/+3
|
* tags cleanup.art2002-02-182-2/+2
|
* add longjmpart2002-02-181-2/+2
|
* Clean up.art2002-02-182-2/+5
|
* cleanart2002-02-182-7/+3
|
* Return a failure if the test fails don't just fall out from main().art2002-02-181-2/+5
|
* Manual cleanup of remaining userland __P use (excluding packages maintained ↵millert2002-02-1711-54/+48
| | | | outside the tree)
* oops, add -U to usageericj2002-02-171-2/+2
|
* add support for connecting too and listening on AF_UNIX sockets.ericj2002-02-172-13/+111
| | | | connect support from dave@arbor.net.. rest by me
* fix pr#2091. patch applied.ericj2002-02-171-2/+2
| | | | | patch from Brian J. Kifiak <bk@rt.fm> should be looked at closer..
* Part one of userland __P removal. Done with a simple regexp with some minor ↵millert2002-02-1633-145/+145
| | | | hand editing to make comments line up correctly. Another pass is forthcoming that handles the cases that could not be done automatically.
* + infpvalchev2002-02-161-2/+2
|
* Simple test for isinf(3) and HUGE_VAL; ok artpvalchev2002-02-162-0/+22
|
* popenart2002-02-161-2/+2
|
* Tests for popen(3). From NetBSD.art2002-02-162-0/+109
|
* Remove references to nonexistent man pages. Ok theo, millert.kjell2002-02-121-2/+1
|
* but... on vax... des_enc.c requires -O1deraadt2002-02-101-1/+2
|
* fix the history refsmickey2002-01-241-2/+2
|
* THREAD_UNLOCK() on error before returning; millert@ ok.fgsch2002-01-231-1/+3
|