1. 22 Jan, 2015 18 commits
  2. 15 Jan, 2015 4 commits
  3. 13 Jan, 2015 3 commits
  4. 09 Jan, 2015 2 commits
  5. 08 Jan, 2015 8 commits
  6. 07 Jan, 2015 1 commit
  7. 06 Jan, 2015 3 commits
  8. 05 Jan, 2015 1 commit
    • Dr. Stephen Henson's avatar
      ECDH downgrade bug fix. · e42a2aba
      Dr. Stephen Henson authored
      
      
      Fix bug where an OpenSSL client would accept a handshake using an
      ephemeral ECDH ciphersuites with the server key exchange message omitted.
      
      Thanks to Karthikeyan Bhargavan for reporting this issue.
      
      CVE-2014-3572
      Reviewed-by: default avatarMatt Caswell <matt@openssl.org>
      
      (cherry picked from commit b15f8769)
      
      Conflicts:
      	CHANGES
      	ssl/s3_clnt.c
      e42a2aba