Skip to content
  1. Jun 10, 2014
    • Hubert Kario's avatar
      add ECC strings to ciphers(1), point out difference between DH and ECDH · 343e5cf1
      Hubert Kario authored
       * Make a clear distinction between DH and ECDH key exchange.
       * Group all key exchange cipher suite identifiers, first DH then ECDH
       * add descriptions for all supported *DH* identifiers
       * add ECDSA authentication descriptions
       * add example showing how to disable all suites that offer no
         authentication or encryption
      343e5cf1
    • Mike Bland's avatar
      Create test/testutil.h for unit test helper macros · 3ead9f37
      Mike Bland authored
      Defines SETUP_TEST_FIXTURE and EXECUTE_TEST, and updates ssl/heartbeat_test.c
      using these macros. SETUP_TEST_FIXTURE makes use of the new TEST_CASE_NAME
      macro, defined to use __func__ or __FUNCTION__ on platforms that support those
      symbols, or to use the file name and line number otherwise. This should fix
      several reported build problems related to lack of C99 support.
      3ead9f37
    • Dr. Stephen Henson's avatar
      Fix null pointer errors. · 7a9d59c1
      Dr. Stephen Henson authored
      PR#3394
      7a9d59c1
  2. Jun 09, 2014
  3. Jun 08, 2014
  4. Jun 07, 2014
  5. Jun 06, 2014
  6. Jun 05, 2014
    • Dr. Stephen Henson's avatar
      Update value to use a free bit. · 5111672b
      Dr. Stephen Henson authored
      5111672b
    • Dr. Stephen Henson's avatar
      Fix for CVE-2014-0195 · 410e444b
      Dr. Stephen Henson authored
      A buffer overrun attack can be triggered by sending invalid DTLS fragments
      to an OpenSSL DTLS client or server. This is potentially exploitable to
      run arbitrary code on a vulnerable client or server.
      
      Fixed by adding consistency check for DTLS fragments.
      
      Thanks to Jüri Aedla for reporting this issue.
      (cherry picked from commit 1632ef744872edc2aa2a53d487d3e79c965a4ad3)
      410e444b
    • Dr. Stephen Henson's avatar
      Fix for CVE-2014-0224 · a91be108
      Dr. Stephen Henson authored
      Only accept change cipher spec when it is expected instead of at any
      time. This prevents premature setting of session keys before the master
      secret is determined which an attacker could use as a MITM attack.
      
      Thanks to KIKUCHI Masashi (Lepidum Co. Ltd.) for reporting this issue
      and providing the initial fix this patch is based on.
      (cherry picked from commit bc8923b1ec9c467755cd86f7848c50ee8812e441)
      a91be108
    • Dr. Stephen Henson's avatar
      Additional CVE-2014-0224 protection. · a7c682fb
      Dr. Stephen Henson authored
      Return a fatal error if an attempt is made to use a zero length
      master secret.
      (cherry picked from commit 006cd708)
      a7c682fb
    • Dr. Stephen Henson's avatar
      Fix CVE-2014-0221 · b4322e1d
      Dr. Stephen Henson authored
      Unnecessary recursion when receiving a DTLS hello request can be used to
      crash a DTLS client. Fixed by handling DTLS hello request without recursion.
      
      Thanks to Imre Rad (Search-Lab Ltd.) for discovering this issue.
      (cherry picked from commit d3152655d5319ce883c8e3ac4b99f8de4c59d846)
      b4322e1d
    • Dr. Stephen Henson's avatar
      Fix CVE-2014-3470 · a5362db4
      Dr. Stephen Henson authored
      Check session_cert is not NULL before dereferencing it.
      (cherry picked from commit 8011cd56)
      a5362db4
  7. Jun 04, 2014
  8. Jun 03, 2014
  9. Jun 02, 2014
  10. Jun 01, 2014