Verify that we have a sensible message len and fail if not
[oweals/openssl.git] / ssl /
2014-12-03 Matt CaswellVerify that we have a sensible message len and fail...
2014-11-28 Richard Levitte[PR3597] Advance to the next state variant when reusing...
2014-11-27 Matt CaswellFix warning in ssl2_enc
2014-11-27 Matt CaswellRemove more references to dtls1_enc
2014-11-27 Matt CaswellCheck EVP_Cipher return values for SSL2
2014-11-27 Matt CaswellDelete unused file
2014-11-27 Matt CaswellAdd checks to the return value of EVP_Cipher to prevent...
2014-11-27 Matt CaswellRemove redundant checks in ssl_cert_dup. This was causi...
2014-11-27 Matt CaswellAdd include of ssl.h which is required by srtp.h
2014-11-26 Matt CaswellFixed memory leak due to incorrect freeing of DTLS...
2014-11-25 Matt CaswellCorrected comments in ssl.h about SSLv23_method and...
2014-11-20 Dr. Stephen HensonFix SuiteB chain checking logic.
2014-11-20 David BenjaminDo not resume a session if the negotiated protocol...
2014-11-20 Emilia KasperEnsure SSL3_FLAGS_CCS_OK (or d1->change_cipher_spec_ok...
2014-11-20 Emilia KasperAlways require an advertised NewSessionTicket message.
2014-11-20 Emilia KasperRemove ssl3_check_finished.
2014-11-20 Emilia KasperSet s->hit when resuming from external pre-shared secret.
2014-11-20 Emilia KasperReset s->tlsext_ticket_expected in ssl_scan_serverhello...
2014-11-19 Dr. Stephen HensonNew option no-ssl3-method which removes SSLv3_*method
2014-11-19 Dr. Stephen HensonProcess signature algorithms before deciding on certifi...
2014-11-18 Matt CaswellAdded RFC 7027 references
2014-11-18 Matt CaswellAdded OPENSSL_NO_EC2M guards around the default EC...
2014-11-10 Daniel Kahn GillmorAllow ECDHE and DHE as forward-compatible aliases for...
2014-10-28 Emilia KasperTighten session ticket handling
2014-10-27 Emilia KasperFix ssltest logic when some protocols are compiled...
2014-10-24 Dr. Stephen HensonCopy negotiated parameters in SSL_set_SSL_CTX.
2014-10-24 Dr. Stephen HensonProcess signature algorithms in ClientHello late.
2014-10-23 Dr. Stephen HensonParse custom extensions after SNI.
2014-10-21 Bodo MoellerFix and improve SSL_MODE_SEND_FALLBACK_SCSV documentation.
2014-10-21 Bodo MoellerWhen processing ClientHello.cipher_suites, don't ignore...
2014-10-21 Kurt RoeckxKeep old method in case of an unsupported protocol
2014-10-15 Geoff ThorpeFix no-ssl3 configuration option
2014-10-15 Dr. Stephen HensonFix for session tickets memory leak.
2014-10-15 Matt CaswellFix SRTP compile issues for windows
2014-10-15 Matt CaswellFix for SRTP Memory Leak
2014-10-15 Bodo MoellerSupport TLS_FALLBACK_SCSV.
2014-09-24 Dr. Stephen HensonDon't allow non-FIPS curves in FIPS mode.
2014-09-24 Emilia KasperRT3067: simplify patch
2014-09-24 Adam LangleyThis change alters the processing of invalid, RSA pre...
2014-09-24 Emilia KasperRT3066: rewrite RSA padding checks to be slightly more...
2014-09-21 Tim HudsonFixed error introduced in commit f2be92b94dad3c6cbdf79d...
2014-09-09 Kurt CancemiRT3506: typo's in ssltest
2014-09-08 Erik AuerswaldRT3301: Discard too-long heartbeat requests
2014-09-08 Martin OlssonRT2843: Remove another spurious close-comment token
2014-09-08 Martin OlssonRT2842: Remove spurious close-comment marker.
2014-09-05 Adam Langleypsk_client_callback, 128-byte id bug.
2014-08-31 Richard LevitteAdd t1_ext and ssl_utst to the VMS build as well.
2014-08-28 Dr. Stephen HensonFix comments, add new test.
2014-08-28 Dr. Stephen HensonRename some callbacks, fix alignment.
2014-08-28 Dr. Stephen HensonUse consistent function naming.
2014-08-28 Dr. Stephen HensonNew function SSL_extension_supported().
2014-08-28 Dr. Stephen HensonNew extension callback features.
2014-08-28 Dr. Stephen HensonCallback revision.
2014-08-28 Dr. Stephen HensonRemove serverinfo checks.
2014-08-28 Dr. Stephen HensonAdd custom extension sanity checks.
2014-08-28 Dr. Stephen HensonCustom extension revision.
2014-08-28 Dr. Stephen HensonRevision of custom extension code.
2014-08-28 Emilia KasperConstant-time utilities
2014-08-26 John FitzgibbonRT2724: Remove extra declaration
2014-08-22 Adam LangleyRT3060: Limit the number of empty records.
2014-08-15 Matt CaswellFixed out-of-bounds read errors in ssl3_get_key_exchange.
2014-08-08 Dr. Stephen HensonFix SRP authentication ciphersuites.
2014-08-06 Dr. Stephen HensonCheck SRP parameters early.
2014-08-06 Dr. Stephen HensonFix SRP ciphersuite DoS vulnerability.
2014-08-06 Gabor TyukaszFix race condition in ssl_parse_serverhello_tlsext
2014-08-06 Emilia KäsperFix DTLS anonymous EC(DH) denial of service
2014-08-06 David BenjaminFix protocol downgrade bug in case of fragmented packets
2014-08-06 Adam LangleyRemove some duplicate DTLS code.
2014-08-06 Matt CaswellApplying same fix as in dtls1_process_out_of_seq_messag...
2014-08-06 Adam LangleyFix return code for truncated DTLS fragment.
2014-08-06 Adam LangleyFix memory leak from zero-length DTLS fragments.
2014-08-06 Matt CaswellFix DTLS handshake message size checks.
2014-08-06 Matt CaswellAdded comment for the frag->reassembly == NULL case...
2014-08-06 Adam LangleyAvoid double free when processing DTLS packets.
2014-08-01 Dr. Stephen Hensonmake update
2014-07-24 Dr. Stephen HensonAdd conditional unit testing interface.
2014-07-15 Dr. Stephen HensonFix DTLS certificate requesting code.
2014-07-14 Dr. Stephen HensonUse more common name for GOST key exchange.
2014-07-13 Peter MosmansAdd names of GOST algorithms.
2014-07-09 Andy PolyakovPlease Clang's sanitizer.
2014-07-05 Andy Polyakovs3_pkt.c: fix typo.
2014-07-05 Dr. Stephen HensonDon't limit message sizes in ssl3_get_cert_verify.
2014-07-04 Dr. Stephen HensonRemove all RFC5878 code.
2014-07-02 Thijs AlkemadeMake disabling last cipher work.
2014-07-01 Ben LaurieFix possible buffer overrun.
2014-06-29 Dr. Stephen HensonFix memory leak.
2014-06-27 Dr. Stephen HensonDon't disable state strings with no-ssl2
2014-06-27 yogesh nagarkarFix compilation with -DSSL_DEBUG -DTLS_DEBUG -DKSSL_DEBUG
2014-06-27 Ken BallouRemove redundant check.
2014-06-27 Tomas MrazDon't advertise ECC ciphersuits in SSLv2 compatible...
2014-06-22 Miod VallatFix off-by-one errors in ssl_cipher_get_evp()
2014-06-22 Matt CaswellRevert "Fix off-by-one errors in ssl_cipher_get_evp()"
2014-06-22 Matt CaswellFixed Windows compilation failure
2014-06-17 Felix Laurie von... Fix signed/unsigned comparisons.
2014-06-17 Richard LevitteRemove unused DANE macros. This should be the last...
2014-06-16 Richard LevitteSpaces were added in some strings for better readabilit...
2014-06-14 Dr. Stephen HensonAccept CCS after sending finished.
2014-06-14 Richard LevitteAdjust VMS build files to the Unix ones
2014-06-14 Richard LevitteMake sure that disabling the MAYLOSEDATA3 warning is...
2014-06-13 Matt CaswellFixed incorrect return code handling in ssl3_final_fini...
next