freebsd-skq/crypto/openssl/apps
simon abe6016909 Prevent cross-site forgery attacks on lukemftpd(8) due to splitting
long commands into multiple requests. [09:01]

Fix incorrect OpenSSL checks for malformed signatures due to invalid
check of return value from EVP_VerifyFinal(), DSA_verify, and
DSA_do_verify. [09:02]

Security:	FreeBSD-SA-09:01.lukemftpd
Security:	FreeBSD-SA-09:02.openssl
Obtained from:	NetBSD [SA-09:01]
Obtained from:	OpenSSL Project [SA-09:02]
Approved by:	so (simon)
2009-01-07 20:17:55 +00:00
..
demoCA
set
app_rand.c
apps.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
apps.h Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
asn1pars.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ca-cert.srl
ca-key.pem
ca-req.pem
ca.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
CA.pl Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
CA.pl.in Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
CA.sh Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
cert.pem
ciphers.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
client.pem
crl2p7.c
crl.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
dgst.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
dh512.pem
dh1024.pem
dh2048.pem
dh4096.pem
dh.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
dhparam.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
dsa512.pem
dsa1024.pem
dsa-ca.pem
dsa-pca.pem
dsa.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
dsap.pem
dsaparam.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
ec.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
ecparam.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
enc.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
engine.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
errstr.c
gendh.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
gendsa.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
genrsa.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
Makefile Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
nseq.c
ocsp.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
oid.cnf
openssl.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
openssl.cnf Resolve conflicts after import of OpenSSL 0.9.8b. 2006-07-29 19:14:51 +00:00
passwd.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
pca-cert.srl
pca-key.pem
pca-req.pem
pkcs7.c
pkcs8.c Vendor import of OpenSSL 0.9.7e. 2005-02-25 05:39:05 +00:00
pkcs12.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
prime.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
privkey.pem
progs.h Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
progs.pl Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
rand.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
req.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
req.pem
rsa8192.pem
rsa.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
rsautl.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s512-key.pem
s512-req.pem
s1024key.pem
s1024req.pem
s_apps.h Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s_cb.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s_client.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s_server.c Vendor import of OpenSSL 0.9.8e. 2007-03-15 20:03:30 +00:00
s_socket.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
s_time.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
server2.pem
server.pem
server.srl
sess_id.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
smime.c Vendor import of OpenSSL 0.9.8d. 2006-10-01 07:38:44 +00:00
speed.c Prevent cross-site forgery attacks on lukemftpd(8) due to splitting 2009-01-07 20:17:55 +00:00
spkac.c Prevent cross-site forgery attacks on lukemftpd(8) due to splitting 2009-01-07 20:17:55 +00:00
testCA.pem
testdsa.h
testrsa.h
timeouts.h Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
verify.c Prevent cross-site forgery attacks on lukemftpd(8) due to splitting 2009-01-07 20:17:55 +00:00
version.c Vendor import of OpenSSL 0.9.8b 2006-07-29 19:10:21 +00:00
winrand.c
x509.c Prevent cross-site forgery attacks on lukemftpd(8) due to splitting 2009-01-07 20:17:55 +00:00