Subject: CVS commit: pkgsrc/security/libtasn1
From: Adam Ciarcinski
Date: 2017-08-18 23:53:47
Message id: 20170818215347.798E6FAD0@cvs.NetBSD.org

Log Message:
release 4.12:
- Corrected so-name version

release 4.11:
- Introduced the ASN1_TIME_ENCODING_ERROR error code to indicate
  an invalid encoding in the DER time fields.
- Introduced flag ASN1_DECODE_FLAG_ALLOW_INCORRECT_TIME. This flag
  allows decoding errors in time fields even when in strict DER mode.
  That is introduced in order to allow toleration of invalid times in
  X.509 certificates (which are common) even though strict DER adherence
  is enforced in other fields.
- Added safety check in asn1_find_node(). That prevents a crash
  when a very long variable name is provided by the developer.
  Note that this to be exploited requires controlling the ASN.1
  definitions used by the developer, i.e., the 'name' parameter of
  asn1_write_value() or asn1_read_value(). The library is
  not designed to protect against malicious manipulation of the
  developer assigned variable names.

Files:
RevisionActionfile
1.70modifypkgsrc/security/libtasn1/Makefile
1.49modifypkgsrc/security/libtasn1/distinfo