CVS: cvs.openbsd.org: src

2014-08-07 Thread Philip Guenther
CVSROOT:/cvs Module name:src Changes by: guent...@cvs.openbsd.org2014/08/07 23:06:56 Modified files: lib/libssl/src/ssl: d1_both.c Log message: Fix CVE-2014-3507, avoid allocating and then leaking a fresh fragment structure when a zero-length fragment is received.

CVS: cvs.openbsd.org: src

2014-08-07 Thread Philip Guenther
CVSROOT:/cvs Module name:src Changes by: guent...@cvs.openbsd.org2014/08/07 22:53:43 Modified files: lib/libssl/src/crypto/asn1: a_object.c lib/libssl/src/crypto/objects: obj_dat.c Log message: Fix CVE-2014-3508, pretty printing and OID validation: - make

CVS: cvs.openbsd.org: www

2014-08-07 Thread Lawrence Teo
CVSROOT:/cvs Module name:www Changes by: l...@cvs.openbsd.org2014/08/07 21:05:50 Modified files: . : 56.html Log message: Fix version numbers of Perl, Less, and NSD. >From Theo Buehler and Daniel Jakots, thank you!

CVS: cvs.openbsd.org: src

2014-08-07 Thread Philip Guenther
CVSROOT:/cvs Module name:src Changes by: guent...@cvs.openbsd.org2014/08/07 16:27:28 Modified files: lib/libssl/src/ssl: t1_lib.c Log message: Correct test reversed during merge of fix for CVE-2014-3509 pointed out by Watson Ladd (watson (at) matasano.com) ok der

CVS: cvs.openbsd.org: src

2014-08-07 Thread Philip Guenther
CVSROOT:/cvs Module name:src Changes by: guent...@cvs.openbsd.org2014/08/07 14:24:12 Modified files: lib/libssl/src/ssl: d1_both.c Log message: Fix CVE-2014-3506, DTLS handshake message size checks. From https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=12

CVS: cvs.openbsd.org: src

2014-08-07 Thread Miod Vallat
CVSROOT:/cvs Module name:src Changes by: m...@cvs.openbsd.org2014/08/07 14:02:23 Modified files: lib/libssl/src/ssl: d1_both.c d1_clnt.c d1_pkt.c s3_both.c s3_enc.c s3_lib.c t1_enc.c Log message: Oops, revert changes commited by mistake. T

CVS: cvs.openbsd.org: src

2014-08-07 Thread Miod Vallat
CVSROOT:/cvs Module name:src Changes by: m...@cvs.openbsd.org2014/08/07 13:46:31 Modified files: lib/libssl/src/ssl: d1_both.c d1_clnt.c d1_pkt.c s23_srvr.c s3_both.c s3_enc.c s3_lib.c t1_enc.c Log message: When you expect a function to re

CVS: cvs.openbsd.org: src

2014-08-07 Thread Lawrence Teo
CVSROOT:/cvs Module name:src Changes by: l...@cvs.openbsd.org2014/08/07 13:03:38 Modified files: usr.bin/signify: signify.1 Log message: Bump example pubkey filenames to /etc/signify/openbsd-56-base.pub for 5.6. ok deraadt@

CVS: cvs.openbsd.org: src

2014-08-07 Thread Reyk Floeter
CVSROOT:/cvs Module name:src Changes by: r...@cvs.openbsd.org2014/08/07 12:21:13 Modified files: usr.sbin/httpd : httpd.8 Log message: Fix and simplify the description of httpd(8)'s signal handling. httpd does not re-executed itself on SIGHUP, it simply reload the co

CVS: cvs.openbsd.org: www

2014-08-07 Thread Ted Unangst
CVSROOT:/cvs Module name:www Changes by: t...@cvs.openbsd.org2014/08/07 07:56:52 Modified files: . : errata55.html Log message: leave a note reminding people to email tech and announce

CVS: cvs.openbsd.org: src

2014-08-07 Thread Florian Obser
CVSROOT:/cvs Module name:src Changes by: flor...@cvs.openbsd.org 2014/08/07 06:43:22 Modified files: usr.sbin/httpd : server_fcgi.c Log message: Don't try to ouput FCGI_STDERR into error.log if there is no data. Problem noticed by naddy@, OK reyk@

CVS: cvs.openbsd.org: src

2014-08-07 Thread Florian Obser
CVSROOT:/cvs Module name:src Changes by: flor...@cvs.openbsd.org 2014/08/07 04:52:34 Modified files: usr.sbin/httpd : server_fcgi.c Log message: Opportunistically try to parse "Status: $code" in the very first response from the fcgi daemon and use that code as HTTP respon