Subject: CVS commit: pkgsrc/security/openssl
From: Takahiro Kambe
Date: 2012-05-11 15:27:27
Message id: 20120511132727.1E1BB175DD@cvs.netbsd.org

Log Message:
Update openssl to 0.9.8x.

 OpenSSL CHANGES
 _______________

 Changes between 0.9.8w and 0.9.8x [10 May 2012]

  *) Sanity check record length before skipping explicit IV in DTLS
     to fix DoS attack.

     Thanks to Codenomicon for discovering this issue using Fuzz-o-Matic
     fuzzing as a service testing platform.
     (CVE-2012-2333)
     [Steve Henson]

  *) Initialise tkeylen properly when encrypting CMS messages.
     Thanks to Solar Designer of Openwall for reporting this issue.
     [Steve Henson]

Files:
RevisionActionfile
1.167modifypkgsrc/security/openssl/Makefile
1.89modifypkgsrc/security/openssl/distinfo