ViewVC Help
View File | Revision Log | Show Annotations | Download File | View Changeset | Root Listing
root/src/stable/0.5/crypto/openssl/doc/ssl/SSL_CTX_set_mode.pod
Revision 6877 - (view) (download) (annotate) - [select for diffs]
Modified Tue Oct 21 22:09:49 2014 UTC (9 years, 6 months ago) by laffer1
File length: 2642 byte(s)
Diff to previous 6736
A flaw in the DTLS SRTP extension parsing code allows an attacker, who
sends a carefully crafted handshake message, to cause OpenSSL to fail
to free up to 64k of memory causing a memory leak.  [CVE-2014-3513].

When an OpenSSL SSL/TLS/DTLS server receives a session ticket the
integrity of that ticket is first verified. In the event of a session
ticket integrity check failing, OpenSSL will fail to free memory
causing a memory leak.  [CVE-2014-3567].

The SSL protocol 3.0, as supported in OpenSSL and other products, supports
CBC mode encryption where it could not adequately check the integrity of
padding, because of the use of non-deterministic CBC padding.  This
protocol weakness makes it possible for an attacker to obtain clear text
data through a padding-oracle attack.

Some client applications (such as browsers) will reconnect using a
downgraded protocol to work around interoperability bugs in older
servers. This could be exploited by an active man-in-the-middle to
downgrade connections to SSL 3.0 even if both sides of the connection
support higher protocols. SSL 3.0 contains a number of weaknesses
including POODLE [CVE-2014-3566].

OpenSSL has added support for TLS_FALLBACK_SCSV to allow applications
to block the ability for a MITM attacker to force a protocol downgrade.

When OpenSSL is configured with "no-ssl3" as a build option, servers
could accept and complete a SSL 3.0 handshake, and clients could be
configured to send them. [CVE-2014-3568].

Obtained from: OpenSSL, FreeBSD

Revision 6736 - (view) (download) (annotate) - [select for diffs]
Modified Tue Sep 2 22:17:40 2014 UTC (9 years, 8 months ago) by laffer1
File length: 2441 byte(s)
Diff to previous 6469
Create 0.5 stable branch for upcoming 0.5-RELEASE

Revision 6469 - (view) (download) (annotate) - [select for diffs]
Modified Sat Dec 7 23:54:44 2013 UTC (10 years, 4 months ago) by laffer1
Original Path: trunk/crypto/openssl/doc/ssl/SSL_CTX_set_mode.pod
File length: 2441 byte(s)
Diff to previous 3
remove cvs2svn prop

Revision 3 - (view) (download) (annotate) - [select for diffs]
Modified Sat Feb 25 02:29:52 2006 UTC (18 years, 2 months ago) by laffer1
Original Path: trunk/crypto/openssl/doc/ssl/SSL_CTX_set_mode.pod
File length: 2441 byte(s)
Copied from: branches/FreeBSD/crypto/openssl/doc/ssl/SSL_CTX_set_mode.pod revision 2
Diff to previous 2
This commit was generated by cvs2svn to compensate for changes in r2, which
included commits to RCS files with non-trunk default branches.
Revision 2 - (view) (download) (annotate) - [select for diffs]
Added Sat Feb 25 02:29:52 2006 UTC (18 years, 2 months ago) by laffer1
Original Path: branches/FreeBSD/crypto/openssl/doc/ssl/SSL_CTX_set_mode.pod
File length: 2441 byte(s)
Imported from FreeBSD 6.0 sources

Convenience Links

Links to HEAD: (view) (download) (annotate)

Compare Revisions

This form allows you to request diffs between any two revisions of this file. For each of the two "sides" of the diff, enter a numeric revision.

  Diffs between and
  Type of Diff should be a