Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 19 Mar 2015 15:29:50 -0700
From:      Xin Li <delphij@delphij.net>
To:        Vsevolod Stakhov <vsevolod@FreeBSD.org>,  ports-committers@freebsd.org, svn-ports-all@freebsd.org,  svn-ports-head@freebsd.org
Subject:   Re: svn commit: r381603 - in head/security/libressl: . security security/libressl security/libressl/files
Message-ID:  <550B4DDE.8060508@delphij.net>
In-Reply-To: <201503191530.t2JFUOD0008431@svn.freebsd.org>
References:  <201503191530.t2JFUOD0008431@svn.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 03/19/15 08:30, Vsevolod Stakhov wrote:
> Author: vsevolod
> Date: Thu Mar 19 15:30:24 2015
> New Revision: 381603
> URL: https://svnweb.freebsd.org/changeset/ports/381603
> QAT: https://qat.redports.org/buildarchive/r381603/
> 
> Log:
>   - Backport the following fixes from openssl [1]:
>   CVE-2015-0207 Segmentation fault in DTLSv1_listen moderate
>   CVE-2015-0209 Use After Free following d2i_ECPrivatekey error low
>   CVE-2015-0286 Segmentation fault in ASN1_TYPE_cmp moderate
>   CVE-2015-0287 ASN.1 structure reuse memory corruption moderate
>   CVE-2015-0289 PKCS7 NULL pointer dereferences moderate
>   - Enable libtls component [2]
>   - Bump portrevision
>   
>   PR:		198681 [1]
>   Submitted by:	Bernard Spil <spil.oss at gmail.com> [1], naddy [2]
> 
> Added:
>   head/security/libressl/security/
>   head/security/libressl/security/libressl/
>   head/security/libressl/security/libressl/files/
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_a__int.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_a__set.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_a__type.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_d2i__pr.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_d2i__pu.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_n__pkey.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_tasn__dec.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_asn1_x__x509.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_ec_ec__asn1.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_pkcs7_pk7__doit.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-crypto_pkcs7_pk7__lib.c   (contents, props changed)
>   head/security/libressl/security/libressl/files/patch-ssl_d1__lib.c   (contents, props changed)

			   ^^^^^^^^^^^^^^^^^^ This doesn't seem right, would you please fix it?


- -- 
Xin LI <delphij@delphij.net>    https://www.delphij.net/
FreeBSD - The Power to Serve!           Live free or die
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.2 (FreeBSD)

iQIcBAEBCgAGBQJVC03cAAoJEJW2GBstM+nsyqQP/27kmDT9++9pI4iASHo+/IPb
0BYnPcDlNLB/BIr5DqlxH/yycNm7PS36phyvTCBITjTBK/NkPlaa1Lz4X6f3/h31
aE2XXYzYqT07maSJ1CQ0KoXATWiIxdnHATSgulFzk0Kk4nsVs3Krj9D4uiQk3cOm
IGBHK1LLLGDj/L41bXY96l5an/hvVGnlvj2Xi7wkJxmFzrR1ibfXutQligIxtbWp
PWucEeL0QiDCAu0HohQikD5v8oR0/Md3j5pqSMvFKou736c94DX7SPqGFgI5ZCCg
hz1qPSieRtvoANTBbnxhCY9u+baxniSvlW1otI08rHkRN7f25/KEoqe8CCNVlKBl
Owb4vYpBCnEt+tmdR3Pnl2qsmJCIKG7VpFjfOYMffxS8dXj4M5nPbqEvXPV7C/Xn
60j9SBJfQ5qdHH2+bpnVws1IA3lhuK8MrodSFNmM7oi0vqrwVjgindfwaXPt8FLG
si8VFPNbkcktikI8k9z/wSBHr7U1i4rIzQgWsy3nOLi6e55h+zLYDV94fpesXfAR
bgsofHEt5U/fZEmkIKWSl60xlm4Kh9/owQTeHHJfSTFx6/l7x4MoLw21DjbXBaw7
xJ3RDwdBK2Sr+BSHdkMisISRrZPZPzXPiLbiE5UpBIaUhfjsjfTQ8s2DxD6blu7Q
L8BTbKNpuGPiLld3BqSa
=+2dJ
-----END PGP SIGNATURE-----



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?550B4DDE.8060508>