forked from pool/openssl
2ebd052507
- update to 1.0.2g (bsc#968044) * Disable weak ciphers in SSLv3 and up in default builds of OpenSSL. Builds that are not configured with "enable-weak-ssl-ciphers" will not provide any "EXPORT" or "LOW" strength ciphers. * Disable SSLv2 default build, default negotiation and weak ciphers. SSLv2 is by default disabled at build-time. Builds that are not configured with "enable-ssl2" will not support SSLv2. Even if "enable-ssl2" is used, users who want to negotiate SSLv2 via the version-flexible SSLv23_method() will need to explicitly call either of: SSL_CTX_clear_options(ctx, SSL_OP_NO_SSLv2); or SSL_clear_options(ssl, SSL_OP_NO_SSLv2); (CVE-2016-0800) * Fix a double-free in DSA code (CVE-2016-0705) * Disable SRP fake user seed to address a server memory leak. Add a new method SRP_VBASE_get1_by_user that handles the seed properly. (CVE-2016-0798) * Fix BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption (CVE-2016-0797) *) Side channel attack on modular exponentiation http://cachebleed.info. (CVE-2016-0702) *) Change the req app to generate a 2048-bit RSA/DSA key by default, if no keysize is specified with default_bits. This fixes an omission in an earlier change that changed all RSA/DSA key generation apps to use 2048 bits by default. (forwarded request 363599 from vitezslav_cizek) OBS-URL: https://build.opensuse.org/request/show/363602 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl?expand=0&rev=130 |
||
---|---|---|
.gitattributes | ||
.gitignore | ||
0001-Axe-builtin-printf-implementation-use-glibc-instead.patch | ||
0001-libcrypto-Hide-library-private-symbols.patch | ||
0005-libssl-Hide-library-private-symbols.patch | ||
baselibs.conf | ||
bsc936563_hack.patch | ||
bug610223.patch | ||
compression_methods_switch.patch | ||
merge_from_0.9.8k.patch | ||
openssl-1.0.0-c_rehash-compat.diff | ||
openssl-1.0.1e-add-suse-default-cipher.patch | ||
openssl-1.0.1e-add-test-suse-default-cipher-suite.patch | ||
openssl-1.0.1e-truststore.diff | ||
openssl-1.0.2a-default-paths.patch | ||
openssl-1.0.2a-fips-ctor.patch | ||
openssl-1.0.2a-fips-ec.patch | ||
openssl-1.0.2a-ipv6-apps.patch | ||
openssl-1.0.2a-new-fips-reqs.patch | ||
openssl-1.0.2a-padlock64.patch | ||
openssl-1.0.2e-fips.patch | ||
openssl-1.0.2g.tar.gz | ||
openssl-1.0.2g.tar.gz.asc | ||
openssl-fips-hidden.patch | ||
openssl-fix-pod-syntax.diff | ||
openssl-gcc-attributes.patch | ||
openssl-missing_FIPS_ec_group_new_by_curve_name.patch | ||
openssl-no-egd.patch | ||
openssl-ocloexec.patch | ||
openssl-pkgconfig.patch | ||
openssl.changes | ||
openssl.keyring | ||
openssl.spec | ||
openssl.test | ||
README-FIPS.txt | ||
README.SUSE |
Please note that the man pages for the openssl libraries and tools have been placed in a package on its own right: openssl-doc Please install the openssl-doc package if you need the man pages, HTML documentation or sample C programs. The C header files and static libraries have also been extracted, they can now be found in the openssl-devel package. Your SuSE Team.