Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (5h)  pkgsrc-2024Q1 (10d)  pkgsrc-2023Q4 (57d)  pkgsrc-2023Q2 (90d)  pkgsrc-2023Q3 (169d) 

2024-05-28 09:57:49 UTC Now

2012-03-13 03:11:32 UTC MAIN commitmail json YAML

Update openssl pacakge to 0.9.8u.

Changes between 0.9.8t and 0.9.8u [12 Mar 2012]

  *) Fix MMA (Bleichenbacher's attack on PKCS #1 v1.5 RSA padding) weakness
    in CMS and PKCS7 code. When RSA decryption fails use a random key for
    content decryption and always return the same error. Note: this attack
    needs on average 2^20 messages so it only affects automated senders. The
    old behaviour can be reenabled in the CMS code by setting the
    CMS_DEBUG_DECRYPT flag: this is useful for debugging and testing where
    an MMA defence is not necessary.
    Thanks to Ivan Nestlerode <inestlerode@us.ibm.com> for discovering
    this issue. (CVE-2012-0884)
    [Steve Henson]

  *) Fix CVE-2011-4619: make sure we really are receiving a
    client hello before rejecting multiple SGC restarts. Thanks to
    Ivan Nestlerode <inestlerode@us.ibm.com> for discovering this bug.
    [Steve Henson]

(taca)