HomeFreeBSD

Import vendor fixes:

Description

Import vendor fixes:

197e0ea Fix for TLS record tampering bug. (CVE-2013-4353).
3462896 For DTLS we might need to retransmit messages from the
previous session so keep a copy of write context in DTLS
retransmission buffers instead of replacing it after
sending CCS. (CVE-2013-6450).
ca98926 When deciding whether to use TLS 1.2 PRF and record hash
algorithms use the version number in the corresponding
SSL_METHOD structure instead of the SSL structure. The
SSL structure version is sometimes inaccurate.
Note: OpenSSL 1.0.2 and later effectively do this already.
(CVE-2013-6449).

Details

Provenance
delphijAuthored on Jan 7 2014, 7:02 PM
Parents
rGed4c5254dd24: Integrate OpenSSL commit 9fe4603b8245425a4c46986ed000fca054231253:
Branches
Unknown
Tags
Unknown

Event Timeline