Skip to content
  1. Jun 12, 2014
  2. Jun 11, 2014
  3. Jun 10, 2014
  4. Jun 09, 2014
    • Dr. Stephen Henson's avatar
      SRP ciphersuite correction. · f472ada0
      Dr. Stephen Henson authored
      SRP ciphersuites do not have no authentication. They have authentication
      based on SRP. Add new SRP authentication flag and cipher string.
      (cherry picked from commit a86b88acc373ac1fb0ca709a5fb8a8fa74683f67)
      f472ada0
    • Dr. Stephen Henson's avatar
      Update strength_bits for 3DES. · 05b22104
      Dr. Stephen Henson authored
      Fix strength_bits to 112 for 3DES.
      (cherry picked from commit 837c203719205ab19b5609b2df7151be8df05687)
      05b22104
  5. Jun 08, 2014
  6. Jun 07, 2014
  7. Jun 05, 2014
    • Dr. Stephen Henson's avatar
      Fix for CVE-2014-0195 · eb6508d5
      Dr. Stephen Henson authored
      A buffer overrun attack can be triggered by sending invalid DTLS fragments
      to an OpenSSL DTLS client or server. This is potentially exploitable to
      run arbitrary code on a vulnerable client or server.
      
      Fixed by adding consistency check for DTLS fragments.
      
      Thanks to Jüri Aedla for reporting this issue.
      (cherry picked from commit 1632ef74)
      eb6508d5