summaryrefslogtreecommitdiff
path: root/src/lib/libssl (follow)
Commit message (Collapse)AuthorAgeFilesLines
* Security fix for CVE-2010-0740OPENBSD_4_5jasper2010-03-311-3/+4
| | | | | | | | | "In TLS connections, certain incorrectly formatted records can cause an OpenSSL client or server to crash due to a read attempt at NULL." http://openssl.org/news/secadv_20100324.txt ok djm@ sthen@
* MFC, original commit by djm@:jasper2010-03-124-8/+11
| | | | | | | | | | | | --------------------------- cherrypick patch from OpenSSL 0.9.8m: *) Always check bn_wexpend() return values for failure. (CVE-2009-3245) [Martin Olsson, Neel Mehta] --------------------------- ok sthen@
* Pull Ben Lauries blind prefix injection fix for CVE-2009-3555 fromsthen2009-11-174-1/+16
| | | | | | | | | openssl 0.9.8l. As suggested by markus@, for -stable the header change is being restricted to a private file, so the minor version is not cranked here. Discussed with markus, djm, deraadt.
* MFC: fixes for OpenSSL ASN.1 invalid memory accesses (CVE-2009-0590 anddjm2009-04-083-2/+16
| | | | CVE-2009-0789).
* This commit was manufactured by cvs2git to create branch 'OPENBSD_4_5'.cvs2svn2009-02-1895-38269/+0
|
* missing ssl_sock_init() call in init_client() (used bydjm2009-01-301-3/+10
| | | | "openssl s_client"), fix an unlikely memory leak
* remove some gratuitous changes that do nothing other than inreasedjm2009-01-301-2/+1
| | | | the size of the diff against openssl mainline
* convert a strdup (into a purpose-allocated buffer) in libcrypto to adjm2009-01-121-2/+3
| | | | memcpy to avoid linker deprecation warnings; pointed out by dkrause@
* openssl-0.9.8j enables RFC3546 TLS extensions by default (e.g. the verydjm2009-01-0913-39/+0
| | | | | useful "server name indication" that allows multihomed TLS server), so remove the #define to disable it here
* adjust Makefile and crank major for openssl-0.9.8jdjm2009-01-0917-16/+56
|
* resolve conflictsdjm2009-01-09301-4804/+6983
|
* This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-094-9/+15
|\ | | | | branch.
| * import openssl-0.9.8jdjm2009-01-0923-96/+299
| |
* | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-09127-3471/+17440
|\ \ | | | | | | branch.
| * | import openssl-0.9.8jdjm2009-01-09439-7223/+24970
| | |
* | | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-0943-95/+1439
|\ \ \ | | | | | | | | branch.
| * | | import openssl-0.9.8jdjm2009-01-0963-558/+2236
| | | |
| * | | This commit was manufactured by cvs2git to create branch 'OPENSSL'.cvs2svn2009-01-054-0/+2088
| | | |
* | | | Add a missing MLINK for BIO_new_socket.oga2009-01-081-1/+2
| | | | | | | | | | | | | | | | Noticed by blambert@. Ok jmc@.
* | | | update to openssl-0.9.8i; tested by several, especially krw@djm2009-01-05136-2902/+4741
| | | |
* | | | fix some cause of bad TEXTREL on i386 and amd64otto2008-09-195-14/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | - global function calls in .init sections (diff makes them via PLT) - calls to global functions in aes-586.S (made static or local) - global variable accesses in rc4-x86_64.S (now made via GOT) from djm@large; ok miod@
* | | | use one call to arc4random_buf() instead of lots of arc4random()djm2008-09-101-8/+2
| | | |
* | | | turn off CAST assembler code (i.e. use C implementation) as it has baddjm2008-09-081-3/+3
| | | | | | | | | | | | | | | | | | | | relocations that lead to libcrypto.so being marked TEXTREL; linker-fu from drahn@ "go ahead" deraadt@
* | | | sparc now requires this bloated library to be -fPICderaadt2008-09-071-1/+5
| | | |
* | | | Fix merge botch.kettenis2008-09-071-3/+0
| | | | | | | | | | | | | | | | ok miod@
* | | | remove duplicate definition of OPENSSL_DSA_MAX_MODULUS_BITS spotteddjm2008-09-061-2/+0
| | | | | | | | | | | | | | | | by dtucker@
* | | | remerge local tweaks, update per-arch configuration headers, updatedjm2008-09-0626-98/+875
| | | | | | | | | | | | | | | | Makefiles, crank shlib_version
* | | | resolve conflictsdjm2008-09-06697-15897/+44294
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2008-09-0620-1/+7194
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import of OpenSSL 0.9.8hdjm2008-09-0662-1452/+13147
| | | |
| * | | import of openssl-0.9.7jdjm2006-06-2714-539/+650
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2008-09-06103-8888/+13893
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import of OpenSSL 0.9.8hdjm2008-09-06763-23808/+54005
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2008-09-06228-38/+70819
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import of OpenSSL 0.9.8hdjm2008-09-06229-871/+71643
| | | |
* | | | Install man pages for the BIO_* libcrypto functions, but not bio.3jsg2008-07-281-1/+126
| | | | | | | | | | | | | | | | | | | | | | | | as the page doesn't directly describe any functions. ok deraadt@
* | | | i have to crank this for a ridiculous reason, to save me about 4 hours of workderaadt2008-07-251-1/+1
| | | |
* | | | remove duplicates; remove des_random_key; remove unused; sort MLINKS; ok jmc@markus2008-05-071-113/+8
| | | |
* | | | fix memory leak (in one case of unaligned buffers); from Markus Kvetterderaadt2008-02-261-2/+3
| | | | | | | | | | | | | | | | ok markus
* | | | Replace use of strcpy(3) and other pointer goo inmoritz2007-10-102-30/+24
| | | | | | | | | | | | | | | | | | | | | | | | SSL_get_shared_ciphers() with strlcat(3). ok deraadt@ markus@
* | | | Fix off-by-one buffer overflow in SSL_get_shared_ciphers().moritz2007-09-272-22/+22
| | | | | | | | | | | | | | | | | | | | | | | | From OpenSSL_0_9_8-stable branch. ok djm@
* | | | Proper use of fseek/fseeko macros.tobias2007-09-101-1/+1
| | | | | | | | | | | | | | | | OK joris@, otto@
* | | | http://openssl.org/news/patch-CVE-2007-3108.txt; ok pval, deraadtmarkus2007-08-211-13/+65
| | | |
* | | | Correctly NUL terminate the message buffer that is used with theclaudio2007-08-061-4/+24
| | | | | | | | | | | | | | | | | | | | -starttls option. Without this openssl s_client -starttls crashed with malloc.conf -> J. OK deraadt@, hshoexer@
* | | | More comment typos from Diego Casati. Including winners like funtion, allmost,krw2007-05-261-1/+1
| | | | | | | | | | | | | | | | oustside, seqencer, toghether, nessissary, etc.
* | | | Add proper checks against fgets failure. From Charles Longeau.ray2007-04-061-1/+2
| | | | | | | | | | | | | | | | OK moritz@, millert@, and jaredy@.
* | | | Add the cRLSign bit by default, so that certs generated using this filecloder2007-03-281-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | will be able to sign CRLs. OK reyk, hshoexer, millert
* | | | remove some bogus *p tests from charles longeautedu2007-03-203-5/+5
| | | | | | | | | | | | | | | | ok deraadt millert
* | | | remove two expired certificates, diff from <Christian_Rusch@genua.de>grunk2007-02-171-97/+0
| | | | | | | | | | | | | | | | ok jakob@
* | | | Fix format string misuse in kssl_err_set(), which is notmoritz2007-01-031-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | called with user-supplied strings at the moment. ok markus@