Skip to content

Releases: quarckster/openssl

OpenSSL 1.1.1d

18 Sep 10:33
OpenSSL_1_1_1d
Compare
Choose a tag to compare

Changelog

  • Fixed a fork protection issue (CVE-2019-1549)
  • Fixed a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
    (CVE-2019-1563)
  • For built-in EC curves, ensure an EC_GROUP built from the curve name is
    used even when parsing explicit parameters
  • Compute ECC cofactors if not provided during EC_GROUP construction
    (CVE-2019-1547)
  • Early start up entropy quality from the DEVRANDOM seed source has been
    improved for older Linux systems
  • Correct the extended master secret constant on EBCDIC systems
  • Use Windows installation paths in the mingw builds (CVE-2019-1552)
  • Changed DH_check to accept parameters with order q and 2q subgroups
  • Significantly reduce secure memory usage by the randomness pools
  • Revert the DEVRANDOM_WAIT feature for Linux systems

OpenSSL 1.1.0l

18 Sep 10:34
OpenSSL_1_1_0l
Compare
Choose a tag to compare

Changelog

  • Fixed a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
    (CVE-2019-1563)
  • For built-in EC curves, ensure an EC_GROUP built from the curve name is
    used even when parsing explicit parameters
  • Compute ECC cofactors if not provided during EC_GROUP construction
    (CVE-2019-1547)
  • Use Windows installation paths in the mingw builds (CVE-2019-1552)

OpenSSL 1.0.2t

18 Sep 10:35
OpenSSL_1_0_2t
Compare
Choose a tag to compare

Changelog

  • Fixed a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
    (CVE-2019-1563)
  • For built-in EC curves, ensure an EC_GROUP built from the curve name is
    used even when parsing explicit parameters
  • Compute ECC cofactors if not provided during EC_GROUP construction
    (CVE-2019-1547)
  • Document issue with installation paths in diverse Windows builds
    (CVE-2019-1552)

OpenSSL 1.1.1c

18 Sep 10:33
Compare
Choose a tag to compare

Changelog

OpenSSL 1.1.0k

18 Sep 10:34
Compare
Choose a tag to compare

Changelog

OpenSSL 1.0.2s

18 Sep 10:35
Compare
Choose a tag to compare
OpenSSL_1_0_2s

OpenSSL 1.0.2s release tag

OpenSSL 1.1.1b

18 Sep 10:33
OpenSSL_1_1_1b
Compare
Choose a tag to compare

Changelog

  • Change the info callback signals for the start and end of a post-handshake
    message exchange in TLSv1.3.
  • Fix a bug in DTLS over SCTP. This breaks interoperability with older versions
    of OpenSSL like OpenSSL 1.1.0 and OpenSSL 1.0.2.

OpenSSL 1.0.2r

18 Sep 10:35
OpenSSL_1_0_2r
Compare
Choose a tag to compare

Changelog

OpenSSL 1.1.1a

18 Sep 10:33
OpenSSL_1_1_1a
Compare
Choose a tag to compare

Changelog

  • Timing vulnerability in DSA signature generation (CVE-2018-0734)
  • Timing vulnerability in ECDSA signature generation (CVE-2018-0735)

OpenSSL 1.1.0j

18 Sep 10:34
OpenSSL_1_1_0j
Compare
Choose a tag to compare

Changelog

  • Timing vulnerability in DSA signature generation (CVE-2018-0734)
  • Timing vulnerability in ECDSA signature generation (CVE-2018-0735)