| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
|
| |
Merge OpenSSL 1.0.2l.
(cherry picked from commit ffd1bb8c599181e0733f8e00d8d8198b4ea6a73b)
|
|
|
|
| |
Merge OpenSSL 1.0.2k.
|
|
|
|
| |
Merge OpenSSL 1.0.2u.
|
|\
| |
| |
| | |
Relnotes: yes
|
|\ \
| |/
| |
| | |
Relnotes: yes
|
|\ \
| |/ |
|
|\ \
| |/ |
|
| | |
|
| | |
|
|\ \
| |/ |
|
|\ \
| |/ |
|
|\ \
| |/ |
|
|\ \
| |/ |
|
|\ \
| |/
| |
| | |
Approved by: so (delphij)
|
| |
| |
| |
| | |
Approved by: benl (maintainer)
|
| |
| |
| |
| |
| | |
Fix "Heartbleed" vulnerability and ECDSA Cache Side-channel
Attack in OpenSSL. [SA-14:06]
|
| |
| |
| |
| | |
Approved by: so (delphij), benl (silence)
|
|\ \
| |/
| |
| | |
Approved by: secteam (simon), benl (silence)
|
|\ \
| |/
| |
| | |
Approved by: benl (maintainer)
|
| |
| |
| |
| |
| |
| | |
Reviewed by: stas
Approved by: benl (maintainer)
MFC after: 3 days
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
cause OpenSSL to parse past the end of the message.
Note: Applications are only affected if they act as a server and call
SSL_CTX_set_tlsext_status_cb on the server's SSL_CTX. This includes
Apache httpd >= 2.3.3, if configured with "SSLUseStapling On".
Security: http://www.openssl.org/news/secadv_20110208.txt
Security: CVE-2011-0014
Obtained from: OpenSSL CVS
|
| |
| |
| |
| |
| | |
Security: CVE-2010-3864
Security: http://www.openssl.org/news/secadv_20101116.txt
|
|\ \
| |/
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This also "reverts" some FreeBSD local changes so we should now
be back to using entirely stock OpenSSL. The local changes were
simple $FreeBSD$ lines additions, which were required in the CVS
days, and the patch for FreeBSD-SA-09:15.ssl which has been
superseded with OpenSSL 0.9.8m's RFC5746 'TLS renegotiation
extension' support.
MFC after: 3 weeks
|
|\ \
| |/
| |
| | |
Approved by: re
|
|/ |
|
| |
|
| |
|
| |
|
|
infringement reasons.
|