Jung-uk Kim
6f9291cea8
Merge OpenSSL 1.0.1m.
2015-03-20 19:16:18 +00:00
Jung-uk Kim
751d29910b
Merge OpenSSL 1.0.1k.
2015-01-08 23:42:41 +00:00
Jung-uk Kim
fa5fddf171
Merge OpenSSL 1.0.1j.
2014-10-15 19:12:05 +00:00
Jung-uk Kim
a93cbc2be8
Merge OpenSSL 1.0.1i.
2014-08-07 18:56:10 +00:00
Jung-uk Kim
94ad176c68
Merge OpenSSL 1.0.1h.
...
Approved by: so (delphij)
2014-06-09 05:50:57 +00:00
Jung-uk Kim
560ede85d4
Merge OpenSSL 1.0.1g.
...
Approved by: benl (maintainer)
2014-04-08 21:06:58 +00:00
Xin LI
25bfde79d6
Fix NFS deadlock vulnerability. [SA-14:05]
...
Fix "Heartbleed" vulnerability and ECDSA Cache Side-channel
Attack in OpenSSL. [SA-14:06]
2014-04-08 18:27:32 +00:00
Jung-uk Kim
de78d5d8fd
Merge OpenSSL 1.0.1f.
...
Approved by: so (delphij), benl (silence)
2014-01-22 19:57:11 +00:00
Jung-uk Kim
09286989d3
Merge OpenSSL 1.0.1e.
...
Approved by: secteam (simon), benl (silence)
2013-02-13 23:07:20 +00:00
Jung-uk Kim
1f13597d10
Merge OpenSSL 1.0.1c.
...
Approved by: benl (maintainer)
2012-07-12 19:30:53 +00:00
Jung-uk Kim
12de4ed299
Merge OpenSSL 0.9.8x.
...
Reviewed by: stas
Approved by: benl (maintainer)
MFC after: 3 days
2012-06-27 18:44:36 +00:00
Simon L. B. Nielsen
0a70456882
Fix Incorrectly formatted ClientHello SSL/TLS handshake messages could
...
cause OpenSSL to parse past the end of the message.
Note: Applications are only affected if they act as a server and call
SSL_CTX_set_tlsext_status_cb on the server's SSL_CTX. This includes
Apache httpd >= 2.3.3, if configured with "SSLUseStapling On".
Security: http://www.openssl.org/news/secadv_20110208.txt
Security: CVE-2011-0014
Obtained from: OpenSSL CVS
2011-02-12 21:30:46 +00:00
Simon L. B. Nielsen
a3ddd25aba
Merge OpenSSL 0.9.8p into head.
...
Security: CVE-2010-3864
Security: http://www.openssl.org/news/secadv_20101116.txt
2010-11-22 18:23:44 +00:00
Simon L. B. Nielsen
6a599222bb
Merge OpenSSL 0.9.8m into head.
...
This also "reverts" some FreeBSD local changes so we should now
be back to using entirely stock OpenSSL. The local changes were
simple $FreeBSD$ lines additions, which were required in the CVS
days, and the patch for FreeBSD-SA-09:15.ssl which has been
superseded with OpenSSL 0.9.8m's RFC5746 'TLS renegotiation
extension' support.
MFC after: 3 weeks
2010-03-13 19:22:41 +00:00
Simon L. B. Nielsen
db522d3ae4
Merge OpenSSL 0.9.8k into head.
...
Approved by: re
2009-06-14 19:45:16 +00:00
Simon L. B. Nielsen
c4a78426be
Flatten OpenSSL vendor tree.
2008-08-23 10:51:00 +00:00
Simon L. B. Nielsen
5471f83ea7
Vendor import of OpenSSL 0.9.8e.
2007-03-15 20:03:30 +00:00
Simon L. B. Nielsen
3b4e3dcb9f
Vendor import of OpenSSL 0.9.8b
2006-07-29 19:10:21 +00:00
Kris Kennaway
f579bf8ec7
Initial import of OpenSSL 0.9.5a
2000-04-13 06:33:22 +00:00
Kris Kennaway
7466462628
Initial import of OpenSSL 0.9.4, sans IDEA and RSA code for patent
...
infringement reasons.
2000-01-10 06:22:05 +00:00