summaryrefslogtreecommitdiffstats
path: root/ssl
AgeCommit message (Expand)Author
2013-02-06Fix for EXP-RC2-CBC-MD5Adam Langley
2013-02-05make updateDr. Stephen Henson
2013-02-05Fix error codes.Dr. Stephen Henson
2013-02-05s3/s3_cbc.c: allow for compilations with NO_SHA256|512.Andy Polyakov
2013-02-05ssl/s3_cbc.c: md_state alignment portability fix.Andy Polyakov
2013-02-05ssl/s3_cbc.c: uint64_t portability fix.Andy Polyakov
2013-02-05Don't access EVP_MD internals directly.Dr. Stephen Henson
2013-02-05Timing fix mitigation for FIPS mode.Dr. Stephen Henson
2013-02-05The cbc functions shouldn't be inside #ifdef OPENSSL_NO_TLSEXTDr. Stephen Henson
2013-02-05Update DTLS code to match CBC decoding in TLS.Ben Laurie
2013-02-05Don't crash when processing a zero-length, TLS >= 1.1 record.Ben Laurie
2013-02-05Fixups.Ben Laurie
2013-02-05Oops. Add missing file.Ben Laurie
2013-02-05Make CBC decoding constant time.Ben Laurie
2013-02-05Add and use a constant-time memcmp.Ben Laurie
2012-12-10PR: 2888Dr. Stephen Henson
2012-10-05backport OCSP fix enhancementDr. Stephen Henson
2012-10-05Backport OCSP fix.Ben Laurie
2012-09-21* ssl/t1_enc.c (tls1_change_cipher_state): Stupid bug. Fortunately inRichard Levitte
2012-05-10Sanity check record length before skipping explicit IV in DTLSDr. Stephen Henson
2012-03-31PR: 2778(part)Dr. Stephen Henson
2012-03-12fix error codeDr. Stephen Henson
2012-03-12manually patch missing part of PR#2756Dr. Stephen Henson
2012-03-09PR: 2756Dr. Stephen Henson
2012-03-07PR: 2755Dr. Stephen Henson
2012-03-06revert PR#2755: it breaks compilationDr. Stephen Henson
2012-03-06PR: 2755Dr. Stephen Henson
2012-03-06PR: 2748Dr. Stephen Henson
2012-02-16Fix bug in CVE-2011-4619: check we have really received a client helloDr. Stephen Henson
2012-01-18Fix for DTLS DoS issue introduced by fix for CVE-2011-4109.Dr. Stephen Henson
2012-01-05Fix for builds without DTLS support.Bodo Möller
2012-01-04Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>, Michael Tuexen <t...Dr. Stephen Henson
2012-01-04Clear bytes used for block padding of SSL 3.0 records. (CVE-2011-4576)Dr. Stephen Henson
2012-01-04Only allow one SGC handshake restart for SSL/TLS. (CVE-2011-4619)Dr. Stephen Henson
2012-01-04Submitted by: Adam Langley <agl@chromium.org>Dr. Stephen Henson
2011-12-26PR: 2326Dr. Stephen Henson
2011-12-02Resolve a stack set-up race condition (if the list of compressionBodo Möller
2011-10-27PR: 2628Dr. Stephen Henson
2011-10-19Oops: this change (http://cvs.openssl.org/chngview?cn=21503)Bodo Möller
2011-10-13In ssl3_clear, preserve s3->init_extra along with s3->rbuf.Bodo Möller
2011-09-26fix signed/unsigned warningDr. Stephen Henson
2011-09-23PR: 2602Dr. Stephen Henson
2011-09-05(EC)DH memory handling fixes.Bodo Möller
2011-09-01PR: 2573Dr. Stephen Henson
2011-07-20PR: 2555Dr. Stephen Henson
2011-07-20PR: 2550Dr. Stephen Henson
2011-06-22PR: 2543Dr. Stephen Henson
2011-05-25PR: 2529Dr. Stephen Henson
2011-05-25Oops use up to date patch for PR#2506Dr. Stephen Henson
2011-05-25PR: 2506Dr. Stephen Henson