pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/security/openssl



Module Name:    pkgsrc
Committed By:   taca
Date:           Fri Jan 15 04:55:30 UTC 2010

Modified Files:
        pkgsrc/security/openssl: Makefile distinfo
        pkgsrc/security/openssl/patches: patch-aa patch-ac patch-af

Log Message:
Update openssl package to 0.9.8l, fixing security problem.
Approved by agc@.

Changes between 0.9.8k and 0.9.8l  [5 Nov 2009]

 *) Disable renegotiation completely - this fixes a severe security
    problem (CVE-2009-3555) at the cost of breaking all
    renegotiation. Renegotiation can be re-enabled by setting
    SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION in s3->flags at
    run-time. This is really not recommended unless you know what
    you're doing.
    [Ben Laurie]


To generate a diff of this commit:
cvs rdiff -u -r1.141 -r1.142 pkgsrc/security/openssl/Makefile
cvs rdiff -u -r1.69 -r1.70 pkgsrc/security/openssl/distinfo
cvs rdiff -u -r1.21 -r1.22 pkgsrc/security/openssl/patches/patch-aa
cvs rdiff -u -r1.36 -r1.37 pkgsrc/security/openssl/patches/patch-ac
cvs rdiff -u -r1.22 -r1.23 pkgsrc/security/openssl/patches/patch-af

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.



Home | Main Index | Thread Index | Old Index