Skip to content
  1. Jun 17, 2014
  2. Jun 16, 2014
  3. Jun 14, 2014
  4. Jun 13, 2014
  5. Jun 12, 2014
  6. Jun 11, 2014
  7. Jun 10, 2014
  8. Jun 09, 2014
  9. Jun 08, 2014
  10. Jun 07, 2014
  11. Jun 06, 2014
  12. Jun 05, 2014
    • Dr. Stephen Henson's avatar
      Update value to use a free bit. · 5111672b
      Dr. Stephen Henson authored
      5111672b
    • Dr. Stephen Henson's avatar
      Fix for CVE-2014-0195 · 410e444b
      Dr. Stephen Henson authored
      A buffer overrun attack can be triggered by sending invalid DTLS fragments
      to an OpenSSL DTLS client or server. This is potentially exploitable to
      run arbitrary code on a vulnerable client or server.
      
      Fixed by adding consistency check for DTLS fragments.
      
      Thanks to Jüri Aedla for reporting this issue.
      (cherry picked from commit 1632ef74)
      410e444b