Path to this page:
./
security/openssl,
Secure Socket Layer and cryptographic library
Branch: pkgsrc-2011Q4,
Version: 0.9.8u,
Package name: openssl-0.9.8u,
Maintainer: pkgsrc-usersThe OpenSSL Project is a collaborative effort to develop a
robust, commercial-grade, full-featured, and Open Source
toolkit implementing the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols as well as
a full-strength general purpose cryptography library. The
project is managed by a worldwide community of volunteers
that use the Internet to communicate, plan, and develop the
OpenSSL toolkit and its related documentation.
MESSAGE.SunOS [+/-]===========================================================================
$NetBSD: MESSAGE.SunOS,v 1.1 2011/01/20 16:25:21 tez Exp $
openssl may dump core on SunOS due to a bug in the Solaris linker which
erroneously pads .init segment with zeros [instead of nops]. Since the
bug is triggered at initialization, it can be seen with a simple test like
'openssl version'.
Some versions of gcc already contain a workaround, and the linker may be
fixed in some release. If you see the problem, there are details and a
fix for gcc at http://www.openssl.org/~appro/values.c which solves the
problem.
See also http://gnats.netbsd.org/43939
===========================================================================
Required to build:[
devel/gmake] [
lang/perl5] [
archivers/gtar-base]
Package options: threads
Master sites: (Expand)
SHA1: 09b4f2d9c4588d8010eac6f4ab0c96ad0e9d66ac
RMD160: e0a7fa3950ca290d0a931a130f8651e54ad2a400
Filesize: 3693.141 KB
Version history: (Expand)
- (2012-03-15) Updated to version: openssl-0.9.8u
- (2012-03-06) Updated to version: openssl-0.9.8tnb1
- (2012-01-19) Updated to version: openssl-0.9.8t
- (2012-01-08) Package added to pkgsrc.se, version openssl-0.9.8s (created)
CVS history: (Expand)
2012-03-14 15:48:33 by Matthias Scheler | Files touched by this commit (3) | |
Log message:
Pullup ticket #3702 - requested by taca
security/openssl: security update
Revisions pulled up:
- security/openssl/Makefile 1.163
- security/openssl/distinfo 1.86
- security/openssl/patches/patch-asn_mime.c deleted
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Mar 13 03:11:32 UTC 2012
Modified Files:
pkgsrc/security/openssl: Makefile distinfo
Removed Files:
pkgsrc/security/openssl/patches: patch-asn_mime.c
Log message:
Update openssl pacakge to 0.9.8u.
Changes between 0.9.8t and 0.9.8u [12 Mar 2012]
*) Fix MMA (Bleichenbacher's attack on PKCS #1 v1.5 RSA padding) weakness
in CMS and PKCS7 code. When RSA decryption fails use a random key for
content decryption and always return the same error. Note: this attack
needs on average 2^20 messages so it only affects automated senders. The
old behaviour can be reenabled in the CMS code by setting the
CMS_DEBUG_DECRYPT flag: this is useful for debugging and testing where
an MMA defence is not necessary.
Thanks to Ivan Nestlerode <inestlerode@us.ibm.com> for discovering
this issue. (CVE-2012-0884)
[Steve Henson]
*) Fix CVE-2011-4619: make sure we really are receiving a
client hello before rejecting multiple SGC restarts. Thanks to
Ivan Nestlerode <inestlerode@us.ibm.com> for discovering this bug.
[Steve Henson]
|
2012-03-06 11:29:30 by Matthias Scheler | Files touched by this commit (3) |
Log message:
Pullup ticket #3698 - requested by pettai
security/openssl: security patch
Revisions pulled up:
- security/openssl/Makefile 1.162
- security/openssl/distinfo 1.85
- security/openssl/patches/patch-asn_mime.c 1.1
---
Module Name: pkgsrc
Committed By: pettai
Date: Mon Mar 5 00:26:55 UTC 2012
Modified Files:
pkgsrc/security/openssl: Makefile distinfo
Added Files:
pkgsrc/security/openssl/patches: patch-asn_mime.c
Log message:
Add fix for CVE-2006-7250
|
2012-01-19 07:11:49 by Steven Drake | Files touched by this commit (2) |
Log message:
Pullup ticket #3656 - requested by taca
security/openssl security fix
Revisions pulled up:
- security/openssl/Makefile 1.160
- security/openssl/distinfo 1.84
---
Module Name: pkgsrc
Committed By: taca
Date: Thu Jan 19 00:51:23 UTC 2012
Modified Files:
pkgsrc/security/openssl: Makefile distinfo
Log message:
Update security/openssl package to 0.9.8t.
OpenSSL CHANGES
_______________
Changes between 0.9.8s and 0.9.8t [18 Jan 2012]
*) Fix for DTLS DoS issue introduced by fix for CVE-2011-4109.
Thanks to Antonio Martin, Enterprise Secure Access Research and
Development, Cisco Systems, Inc. for discovering this bug and
preparing a fix. (CVE-2012-0050)
[Antonio Martin]
|