Don't crash when processing a zero-length, TLS >= 1.1 record.
[openssl.git] / ssl /
2013-02-05 Ben LaurieDon't crash when processing a zero-length, TLS >= 1...
2013-02-05 Ben LaurieFixups from previous commit.
2013-02-05 Ben LaurieOops. Add missing file.
2013-02-05 Ben LaurieMake CBC decoding constant time.
2013-02-05 Ben LaurieAdd and use a constant-time memcmp.
2012-12-10 Dr. Stephen HensonPR: 2888
2012-11-22 Dr. Stephen Hensonreject zero length point format list or supported curve...
2012-10-05 Dr. Stephen Hensonbackport OCSP fix enhancement
2012-10-04 Ben LaurieBackport OCSP Stapling fix.
2012-09-21 Richard Levitte* ssl/t1_enc.c (tls1_change_cipher_state): Stupid bug...
2012-05-16 Andy Polyakovs2_clnt.c: compensate for compiler bug [from HEAD].
2012-05-10 Dr. Stephen HensonSanity check record length before skipping explicit...
2012-04-16 Andy PolyakovOPENSSL_NO_SOCK fixes [from HEAD].
2012-04-15 Andy Polyakovs3_srvr.c: fix typo [from HEAD].
2012-03-31 Dr. Stephen HensonPR: 2778(part)
2012-03-12 Dr. Stephen Hensonfix error code
2012-03-09 Dr. Stephen HensonPR: 2756
2012-03-06 Dr. Stephen HensonPR: 2755
2012-03-06 Dr. Stephen HensonPR: 2748
2012-02-16 Dr. Stephen HensonFix bug in CVE-2011-4619: check we have really received...
2012-01-18 Dr. Stephen HensonFix for DTLS DoS issue introduced by fix for CVE-2011...
2012-01-05 Bodo MöllerFix for builds without DTLS support.
2012-01-04 Dr. Stephen HensonSubmitted by: Robin Seggelmann <seggelmann@fh-muenster...
2012-01-04 Dr. Stephen Hensonadd missing part for SGC restart fix (CVE-2011-4619)
2012-01-04 Dr. Stephen HensonClear bytes used for block padding of SSL 3.0 records...
2012-01-04 Dr. Stephen HensonOnly allow one SGC handshake restart for SSL/TLS. ...
2012-01-04 Dr. Stephen HensonSubmitted by: Adam Langley <agl@chromium.org>
2011-12-26 Dr. Stephen HensonPR: 2326
2011-12-02 Bodo MöllerResolve a stack set-up race condition (if the list...
2011-10-27 Dr. Stephen HensonPR: 2628
2011-10-27 Dr. Stephen HensonPR: 2628
2011-10-13 Bodo MöllerIn ssl3_clear, preserve s3->init_extra along with s3...
2011-09-26 Dr. Stephen Hensonfix signed/unsigned warning
2011-09-23 Dr. Stephen HensonPR: 2602
2011-09-05 Bodo Möller(EC)DH memory handling fixes.
2011-09-01 Dr. Stephen HensonPR: 2573
2011-08-14 Dr. Stephen HensonRemove hard coded ecdsaWithSHA1 hack in ssl routines...
2011-07-20 Dr. Stephen HensonPR: 2555
2011-07-20 Dr. Stephen HensonPR: 2550
2011-06-22 Dr. Stephen HensonPR: 2543
2011-06-08 Dr. Stephen Hensonfix memory leak
2011-05-25 Dr. Stephen HensonPR: 2533
2011-05-25 Dr. Stephen HensonPR: 2529
2011-05-25 Dr. Stephen HensonOops use up to date patch for PR#2506
2011-05-25 Dr. Stephen HensonPR: 2506
2011-05-25 Dr. Stephen HensonPR: 2505
2011-05-19 Dr. Stephen Hensonset encodedPoint to NULL after freeing it
2011-04-03 Dr. Stephen HensonPR: 2462
2011-04-03 Dr. Stephen HensonPR: 2458
2011-04-03 Dr. Stephen HensonPR: 2457
2011-03-25 Richard LevitteCorrections to the VMS build system.
2011-03-25 Richard LevitteFor VMS, implement the possibility to choose 64-bit...
2011-03-19 Richard LevitteApply all the changes submitted by Steven M. Schweda...
2011-02-08 Bodo MöllerOCSP stapling fix (OpenSSL 0.9.8r/1.0.0d) OpenSSL_1_0_0d
2011-02-03 Bodo MöllerAssorted bugfixes:
2011-01-04 Dr. Stephen HensonSince DTLS 1.0 is based on TLS 1.1 we should never...
2010-12-14 Richard LevitteFirst attempt at adding the possibility to set the...
2010-12-02 Dr. Stephen Hensonmake update
2010-12-02 Dr. Stephen Hensonfix for CVE-2010-4180
2010-11-25 Dr. Stephen HensonPR: 2240
2010-11-24 Ben LaurieJ-PAKE was not correctly checking values, which could...
2010-11-16 Dr. Stephen HensonDon't assume a decode error if session tlsext_ecpointfo...
2010-11-16 Dr. Stephen Hensonfix CVE-2010-3864
2010-11-14 Dr. Stephen HensonGet correct GOST private key instead of just assuming...
2010-10-10 Dr. Stephen HensonPR: 2314
2010-09-05 Ben LaurieOops. Make depend on a standard configuration.
2010-09-05 Ben LaurieMake depend.
2010-06-15 Dr. Stephen HensonFix warnings (From HEAD, original patch by Ben).
2010-05-17 Dr. Stephen HensonPR: 2259
2010-05-03 Dr. Stephen HensonPR: 2230
2010-04-14 Dr. Stephen Hensonfix signed/unsigned comparison warnings
2010-04-14 Dr. Stephen HensonPR: 2230
2010-04-14 Dr. Stephen HensonPR: 2229
2010-04-14 Dr. Stephen HensonPR: 2228
2010-04-13 Richard LevitteSpelling
2010-04-13 Richard LevitteUndo the previous change, it was incorrect in this...
2010-04-13 Richard LevitteThird argument to dtls1_buffer_record is by reference
2010-04-07 Dr. Stephen HensonAdd SHA2 algorithms to SSL_library_init(). Although...
2010-04-06 Dr. Stephen HensonPR: 2218
2010-04-06 Dr. Stephen HensonPR: 2219
2010-04-06 Dr. Stephen HensonPR: 2223
2010-03-25 Bodo MöllerFix for "Record of death" vulnerability CVE-2010-0740.
2010-03-24 Dr. Stephen HensonPR: 1731 and maybe 2197
2010-03-03 Dr. Stephen HensonSubmitted by: Tomas Hoger <thoger@redhat.com>
2010-03-01 Dr. Stephen Hensonmake USE_CRYPTODEV_DIGESTS work
2010-02-28 Dr. Stephen Hensonalgorithms field has changed in 1.0.0 and later: update
2010-02-27 Dr. Stephen HensonAdd Kerberos fix which was in 0.9.8-stable but never...
2010-02-17 Dr. Stephen HensonOR default SSL_OP_LEGACY_SERVER_CONNECT so existing...
2010-02-17 Dr. Stephen HensonAllow renegotiation if SSL_OP_LEGACY_SERVER_CONNECT...
2010-02-16 Dr. Stephen HensonPR: 2171
2010-02-02 Dr. Stephen HensonPR: 2161
2010-02-01 Dr. Stephen HensonPR: 2160
2010-02-01 Dr. Stephen HensonPR: 2159
2010-01-26 Dr. Stephen HensonPR: 1949
2010-01-26 Dr. Stephen Hensonoops
2010-01-26 Dr. Stephen Hensonexport OPENSSL_isservice and make update
2010-01-25 Richard LevitteCompile t1_reneg on VMS as well.
2010-01-24 Dr. Stephen HensonPR: 2153, 2125
2010-01-24 Dr. Stephen HensonThe fix for PR#1949 unfortunately broke cases where...
2010-01-22 Dr. Stephen HensonIf legacy renegotiation is not permitted then send...
next