freebsd-dev/crypto/openssl/ssl
Simon L. B. Nielsen a0ddfe4e72 Import DTLS security fix from upstream OpenSSL_0_9_8-stable branch.
From the OpenSSL advisory:

	Andy Polyakov discovered a flaw in OpenSSL's DTLS
	implementation which could lead to the compromise of clients
	and servers with DTLS enabled.

	DTLS is a datagram variant of TLS specified in RFC 4347 first
	supported in OpenSSL version 0.9.8. Note that the
	vulnerabilities do not affect SSL and TLS so only clients and
	servers explicitly using DTLS are affected.

	We believe this flaw will permit remote code execution.

Security:	CVE-2007-4995
Security:	http://www.openssl.org/news/secadv_20071012.txt
2007-10-18 20:19:33 +00:00
..
bio_ssl.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
d1_both.c Import DTLS security fix from upstream OpenSSL_0_9_8-stable branch. 2007-10-18 20:19:33 +00:00
d1_clnt.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
d1_enc.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
d1_lib.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
d1_meth.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
d1_pkt.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
d1_srvr.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
dtls1.h Import DTLS security fix from upstream OpenSSL_0_9_8-stable branch. 2007-10-18 20:19:33 +00:00
kssl_lcl.h Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
kssl.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
kssl.h Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
Makefile Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s2_clnt.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
s2_enc.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s2_lib.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s2_meth.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s2_pkt.c Vendor import of OpenSSL 0.9.7d. 2004-03-17 15:49:33 +00:00
s2_srvr.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s3_both.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s3_clnt.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s3_enc.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s3_lib.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s3_meth.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s3_pkt.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s3_srvr.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s23_clnt.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s23_lib.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s23_meth.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s23_pkt.c Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
s23_srvr.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
ssl2.h Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
ssl3.h Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ssl23.h Initial import of OpenSSL 0.9.4, sans IDEA and RSA code for patent 2000-01-10 06:22:05 +00:00
ssl_algs.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
ssl_asn1.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ssl_cert.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
ssl_ciph.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
ssl_err2.c Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
ssl_err.c Import DTLS security fix from upstream OpenSSL_0_9_8-stable branch. 2007-10-18 20:19:33 +00:00
ssl_lib.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
ssl_locl.h Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
ssl_rsa.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ssl_sess.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
ssl_stat.c Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
ssl_task.c Vendor import of OpenSSL release 0.9.7. This release includes 2003-01-28 21:43:22 +00:00
ssl_txt.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ssl.h Import DTLS security fix from upstream OpenSSL_0_9_8-stable branch. 2007-10-18 20:19:33 +00:00
ssltest.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
t1_clnt.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
t1_enc.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
t1_lib.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
t1_meth.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
t1_srvr.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
tls1.h Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00