Skip to content
  1. Jun 03, 2018
  2. Apr 03, 2018
  3. Mar 28, 2018
  4. Mar 19, 2018
  5. Mar 15, 2018
  6. Feb 28, 2018
  7. Feb 23, 2018
  8. Feb 06, 2018
  9. Jan 09, 2018
  10. Jan 07, 2018
  11. May 11, 2017
  12. Feb 08, 2017
  13. Feb 07, 2017
  14. Jan 26, 2017
    • Andy Polyakov's avatar
      crypto/evp: harden AEAD ciphers. · 2198b3a5
      Andy Polyakov authored
      
      
      Originally a crash in 32-bit build was reported CHACHA20-POLY1305
      cipher. The crash is triggered by truncated packet and is result
      of excessive hashing to the edge of accessible memory. Since hash
      operation is read-only it is not considered to be exploitable
      beyond a DoS condition. Other ciphers were hardened.
      
      Thanks to Robert Święcki for report.
      
      CVE-2017-3731
      
      Reviewed-by: default avatarRich Salz <rsalz@openssl.org>
      2198b3a5
  15. Jan 25, 2017
  16. Oct 18, 2016
  17. Jul 16, 2016
  18. Jun 14, 2016
  19. May 24, 2016
  20. May 17, 2016
  21. May 02, 2016
  22. Apr 20, 2016
  23. Apr 13, 2016
  24. Mar 20, 2016
  25. Mar 18, 2016
  26. Feb 05, 2016
  27. Jan 12, 2016
  28. Dec 10, 2015
  29. Nov 09, 2015
  30. Aug 14, 2015
  31. Jul 06, 2015
  32. Jun 08, 2015