免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1020 | 回复: 0

LibreSSL 2.3.9 and 2.4.4 released [复制链接]

论坛徽章:
223
2022北京冬奥会纪念版徽章
日期:2015-08-10 16:30:32操作系统版块每日发帖之星
日期:2016-05-10 19:22:58操作系统版块每日发帖之星
日期:2016-02-18 06:20:00操作系统版块每日发帖之星
日期:2016-03-01 06:20:00操作系统版块每日发帖之星
日期:2016-03-02 06:20:0015-16赛季CBA联赛之上海
日期:2019-09-20 12:29:3219周年集字徽章-周
日期:2019-10-01 20:47:4815-16赛季CBA联赛之八一
日期:2020-10-23 18:30:5320周年集字徽章-20	
日期:2020-10-28 14:14:2615-16赛季CBA联赛之广夏
日期:2023-02-25 16:26:26CU十四周年纪念徽章
日期:2023-04-13 12:23:10操作系统版块每日发帖之星
日期:2016-05-10 19:22:58
发表于 2016-11-08 21:05 |显示全部楼层
We have released LibreSSL 2.3.9 and 2.4.4, which are availeble in the
LibreSSL directory of your local OpenBSD mirror. Both include the following
reliability change:

    * Avoid continual processing of an unlimited number of TLS records,
      which can cause a denial-of-service condition. CVE-2016-8610

LibreSSL 2.4.4 also includes these reliability improvements:

    * In X509_cmp_time(), pass asn1_time_parse() the tag of the field
      being parsed so that a malformed GeneralizedTime field is recognized as
      an error instead of potentially being interpreted as if it was a valid
      UTCTime.

    * Improve ticket validity checking when tlsext_ticket_key_cb()
      callback chooses a different HMAC algorithm.

    * Check for packets with a truncated DTLS cookie.

    * Detect zero-length encrypted session data early, instead of when
      malloc(0) fails or the HMAC check fails.

    * Check for and handle failure of HMAC_{Update,Final} or
      EVP_DecryptUpdate()

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP