summaryrefslogtreecommitdiffstats
AgeCommit message (Expand)Author
2016-11-26apps/speed.c: Fix crash when config loading failsOpenSSL_1_0_1-stableVitezslav Cizek
2016-11-25modes/ctr128.c: fix false carry in counter increment procedure.Andy Polyakov
2016-11-04Missed a mention of RTRich Salz
2016-11-02Secure our notification email.Richard Levitte
2016-11-01Fix grammar-o in CONTRIBUTINGBenjamin Kaduk
2016-10-25Fix leak of secrecy in ecdh_compute_key()Dr. Matthias St. Pierre
2016-10-14Degrade 3DES to MEDIUM in SSL2Vitezslav Cizek
2016-10-13RT is put out to pastureRich Salz
2016-09-22Prepare for 1.0.1v-devMatt Caswell
2016-09-22Prepare for 1.0.1u releaseOpenSSL_1_0_1uMatt Caswell
2016-09-22Updates CHANGES and NEWS for new releaseMatt Caswell
2016-09-22Avoid KCI attack for GOSTDmitry Belyavsky
2016-09-22Fix OCSP Status Request extension unbounded memory growthMatt Caswell
2016-09-21update default dependency optionsDr. Stephen Henson
2016-09-21Make message buffer slightly larger than message.Dr. Stephen Henson
2016-09-21Use SSL3_HM_HEADER_LENGTH instead of 4.Dr. Stephen Henson
2016-09-21Remove unnecessary check.Dr. Stephen Henson
2016-09-21Fix small OOB reads.Dr. Stephen Henson
2016-08-26Fix SSL_export_keying_material() for DTLS1_BAD_VERDavid Woodhouse
2016-08-24Avoid overflow in MDC2_Update()Dr. Stephen Henson
2016-08-24SWEET32 (CVE-2016-2183): Move DES from HIGH to MEDIUMRich Salz
2016-08-23Sanity check ticket length.Dr. Stephen Henson
2016-08-22Fix overflow check in BN_bn2dec()Kazuki Yamaguchi
2016-08-22Prevent DTLS Finished message injectionMatt Caswell
2016-08-22Fix DTLS buffered message DoS attackMatt Caswell
2016-08-20Fix off by 1 in ASN1_STRING_set()Kurt Roeckx
2016-08-19RT3940: For now, just document the issue.Rich Salz
2016-08-19Update function error codeMatt Caswell
2016-08-19Fix DTLS replay protectionMatt Caswell
2016-08-19Fix DTLS unprocessed records bugMatt Caswell
2016-08-16make update to have PEM_R_HEADER_TOO_LONG definedRichard Levitte
2016-08-16Limit reads in do_b2i_bio()Dr. Stephen Henson
2016-08-16Check for errors in BN_bn2dec()Dr. Stephen Henson
2016-08-16Check for errors in a2d_ASN1_OBJECT()Dr. Stephen Henson
2016-08-05Sanity check input length in OPENSSL_uni2asc().Dr. Stephen Henson
2016-08-05Leak fixes.Dr. Stephen Henson
2016-08-04Return error when trying to print invalid ASN1 integerKurt Roeckx
2016-08-04Limit recursion depth in old d2i_ASN1_bytes functionDr. Stephen Henson
2016-08-04Check for overflows in i2d_ASN1_SET()Dr. Stephen Henson
2016-08-03Calculate sequence length properly.Dr. Stephen Henson
2016-08-03include <limits.h>Dr. Stephen Henson
2016-08-02Check for overflows in ASN1_object_size().Dr. Stephen Henson
2016-08-02Check for overlows and error return from ASN1_object_size()Dr. Stephen Henson
2016-07-22Fix OOB read in TS_OBJ_print_bio().Dr. Stephen Henson
2016-06-30Convert memset calls to OPENSSL_cleanseMatt Caswell
2016-06-30Allow proxy certs to be present when verifying a chainRichard Levitte
2016-06-30Fix proxy certificate pathlength verificationRichard Levitte
2016-06-30Check that the subject name in a proxy cert complies to RFC 3820Richard Levitte
2016-06-27Change usage of RAND_pseudo_bytes to RAND_bytesMatt Caswell
2016-06-07More fix DSA, preserve BN_FLG_CONSTTIMEMatt Caswell