CVSROOT: /cvs Module name: ports Changes by: t...@cvs.openbsd.org 2024/06/04 10:33:55
Modified files: security/openssl/3.1: Makefile distinfo Log message: Update to OpenSSL 3.1.6 A use-after-free after SSL_free_buffers() and what feels like the 100th issue in EVP_PKEY_check*. This time it's DSA's turn to DoS the lib. In addition there's a new config switch relating to atexit() (need to look more closely) plus unbounded memory growth in some TLSv1.3 configs (which I forgot to mention for 3.2.2).