|
|
|
|
Changelog for openssl-debuginfo-0.9.7a-33.24.i386.rpm :
Wed Oct 17 00:00:00 2007 Tomas Mraz 0.9.7a-33.24 - CVE-2007-3108 remove conditionals in BN_div, BN_mod and final Montgomery reduction (#250579) - CVE-2007-5135 off by one buffer overflow in SSL_get_shared_ciphers (#309841)
Mon Mar 19 23:00:00 2007 Tomas Mraz 0.9.7a-33.23 - improve handling of certificates with EXFLAG_NSCERT set (#200880)
Tue Oct 3 00:00:00 2006 Tomas Mraz 0.9.7a-33.22 - CVE-2006-2940 fix was incorrect (#208744)
Fri Sep 29 00:00:00 2006 Tomas Mraz 0.9.7a-33.21 - fix CVE-2006-2937 - mishandled error on ASN.1 parsing (#207276) - fix CVE-2006-2940 - parasitic public keys DoS (#207274) - fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940) - fix CVE-2006-4343 - sslv2 client DoS (#206940)
Wed Sep 6 00:00:00 2006 Tomas Mraz 0.9.7a-33.18 - fix CVE-2006-4339 - prevent attack on PKCS#1 v1.5 signatures (#205180) - don\'t overwrite customized ca-bundle.pem on upgrade (#170740)
Fri Oct 7 00:00:00 2005 Tomas Mraz 0.9.7a-33.17 - fix CAN-2005-2969 - remove SSL_OP_MSIE_SSLV2_RSA_PADDING which disables the countermeasure against man in the middle attack in SSLv2 (#169863) - more fixes for constant time/memory access for DSA signature algorithm
Wed Jun 22 00:00:00 2005 Tomas Mraz 0.9.7a-33.16 - rebuild
Fri May 20 00:00:00 2005 Tomas Mraz 0.9.7a-33.15 - fix CAN-2005-0109 - use constant time/memory access mod_exp so bits of private key aren\'t leaked by cache eviction (#157631)
Wed Mar 2 23:00:00 2005 Nalin Dahyabhai 0.9.7a-33.14 - rebuild
Fri Nov 19 23:00:00 2004 Nalin Dahyabhai 0.9.7a-33.13 - remove der_chop, as upstream cvs has done (CAN-2004-0975, #136302)
Wed Jun 23 00:00:00 2004 Phil Knirsch 0.9.7a-33.12 - Updated ICA engine patch from IBM to latest upstream version. - Updated libica to latest upstream version.
Tue Jun 15 00:00:00 2004 Phil Knirsch 0.9.7a-33.11 - Updated ICA engine patch from IBM to latest upstream version.
Tue Mar 16 23:00:00 2004 Joe Orton 0.9.7a-33.10 - rebuild
Tue Mar 16 23:00:00 2004 Phil Knirsch 0.9.7a-33.4 - Fixed libica filespec.
Mon Mar 8 23:00:00 2004 Joe Orton 0.9.7a-33.3 - add security fixes for CAN-2004-0079, CAN-2004-0112
Tue Mar 2 23:00:00 2004 Elliot Lee - rebuilt
Thu Feb 26 23:00:00 2004 Phil Knirsch 0.9.7a-32 - Updated libica to latest upstream version 1.3.5.
Tue Feb 17 23:00:00 2004 Phil Knirsch 0.9.7a-31 - Update ICA crypto engine patch from IBM to latest version.
Fri Feb 13 23:00:00 2004 Elliot Lee - rebuilt
Fri Feb 13 23:00:00 2004 Phil Knirsch 0.9.7a-29 - rebuilt
Wed Feb 11 23:00:00 2004 Phil Knirsch 0.9.7a-28 - Fixed libica build.
Wed Feb 4 23:00:00 2004 Nalin Dahyabhai - add \"-ldl\" to link flags added for Linux-on-ARM (#99313)
Wed Feb 4 23:00:00 2004 Joe Orton 0.9.7a-27 - updated ca-bundle.crt: removed expired GeoTrust roots, added freessl.com root, removed trustcenter.de Class 0 root
Sun Nov 30 23:00:00 2003 Tim Waugh 0.9.7a-26 - Fix link line for libssl (bug #111154).
Sat Oct 25 00:00:00 2003 Nalin Dahyabhai 0.9.7a-25 - add dependency on zlib-devel for the -devel package, which depends on zlib symbols because we enable zlib for libssl (#102962)
Sat Oct 25 00:00:00 2003 Phil Knirsch 0.9.7a-24 - Use /dev/urandom instead of PRNG for libica. - Apply libica-1.3.5 fix for /dev/urandom in icalinux.c - Use latest ICA engine patch from IBM.
Sun Oct 5 00:00:00 2003 Nalin Dahyabhai 0.9.7a-22.1 - rebuild
Thu Oct 2 00:00:00 2003 Nalin Dahyabhai 0.9.7a-22 - rebuild (22 wasn\'t actually built, fun eh?)
Wed Oct 1 00:00:00 2003 Nalin Dahyabhai 0.9.7a-23 - re-disable optimizations on ppc64
Wed Oct 1 00:00:00 2003 Joe Orton - add a_mbstr.c fix for 64-bit platforms from CVS
Wed Oct 1 00:00:00 2003 Nalin Dahyabhai 0.9.7a-22 - add -Wa,--noexecstack to RPM_OPT_FLAGS so that assembled modules get tagged as not needing executable stacks
Tue Sep 30 00:00:00 2003 Nalin Dahyabhai 0.9.7a-21 - rebuild
Fri Sep 26 00:00:00 2003 Nalin Dahyabhai - re-enable optimizations on ppc64
Fri Sep 26 00:00:00 2003 Nalin Dahyabhai - remove exclusivearch
Thu Sep 25 00:00:00 2003 Nalin Dahyabhai 0.9.7a-20 - only parse a client cert if one was requested - temporarily exclusivearch for %{ix86}
Wed Sep 24 00:00:00 2003 Nalin Dahyabhai - add security fixes for protocol parsing bugs (CAN-2003-0543, CAN-2003-0544) and heap corruption (CAN-2003-0545) - update RHNS-CA-CERT files - ease back on the number of threads used in the threading test
Thu Sep 18 00:00:00 2003 Matt Wilson 0.9.7a-19 - rebuild to fix gzipped file md5sums (#91211)
Tue Aug 26 00:00:00 2003 Phil Knirsch 0.9.7a-18 - Updated libica to version 1.3.4.
Fri Jul 18 00:00:00 2003 Nalin Dahyabhai 0.9.7a-17 - rebuild
Wed Jul 16 00:00:00 2003 Nalin Dahyabhai 0.9.7a-10.9 - free the kssl_ctx structure when we free an SSL structure (#99066)
Fri Jul 11 00:00:00 2003 Nalin Dahyabhai 0.9.7a-16 - rebuild
Fri Jul 11 00:00:00 2003 Nalin Dahyabhai 0.9.7a-15 - lower thread test count on s390x
Wed Jul 9 00:00:00 2003 Nalin Dahyabhai 0.9.7a-14 - rebuild
Fri Jun 27 00:00:00 2003 Nalin Dahyabhai 0.9.7a-13 - disable assembly on arches where it seems to conflict with threading
Fri Jun 27 00:00:00 2003 Phil Knirsch 0.9.7a-12 - Updated libica to latest upstream version 1.3.0
Thu Jun 12 00:00:00 2003 Nalin Dahyabhai 0.9.7a-9.9 - rebuild
Thu Jun 12 00:00:00 2003 Nalin Dahyabhai 0.9.7a-11 - rebuild
Wed Jun 11 00:00:00 2003 Nalin Dahyabhai 0.9.7a-10 - ubsec: don\'t stomp on output data which might also be input data
Wed Jun 11 00:00:00 2003 Nalin Dahyabhai 0.9.7a-9 - temporarily disable optimizations on ppc64
Tue Jun 10 00:00:00 2003 Nalin Dahyabhai - backport fix for engine-used-for-everything from 0.9.7b - backport fix for prng not being seeded causing problems, also from 0.9.7b - add a check at build-time to ensure that RSA is thread-safe - keep perlpath from stomping on the libica configure scripts
Sat Jun 7 00:00:00 2003 Nalin Dahyabhai - thread-safety fix for RSA blinding
Thu Jun 5 00:00:00 2003 Elliot Lee 0.9.7a-8 - rebuilt
Sat May 31 00:00:00 2003 Phil Knirsch 0.9.7a-7 - Added libica-1.2 to openssl (featurerequest).
Thu Apr 17 00:00:00 2003 Nalin Dahyabhai 0.9.7a-6 - fix building with incorrect flags on ppc64
Wed Mar 19 23:00:00 2003 Nalin Dahyabhai 0.9.7a-5 - add patch to harden against Klima-Pokorny-Rosa extension of Bleichenbacher\'s attack (CAN-2003-0131)
Mon Mar 17 23:00:00 2003 Nalin Dahyabhai 0.9.7a-4 - add patch to enable RSA blinding by default, closing a timing attack (CAN-2003-0147)
Wed Mar 5 23:00:00 2003 Nalin Dahyabhai 0.9.7a-3 - disable use of BN assembly module on x86_64, but continue to allow inline assembly (#83403)
Thu Feb 27 23:00:00 2003 Nalin Dahyabhai 0.9.7a-2 - disable EC algorithms
Wed Feb 19 23:00:00 2003 Nalin Dahyabhai 0.9.7a-1 - update to 0.9.7a
Wed Feb 19 23:00:00 2003 Nalin Dahyabhai 0.9.7-8 - add fix to guard against attempts to allocate negative amounts of memory - add patch for CAN-2003-0078, fixing a timing attack
Thu Feb 13 23:00:00 2003 Elliot Lee 0.9.7-7 - Add openssl-ppc64.patch
Mon Feb 10 23:00:00 2003 Nalin Dahyabhai 0.9.7-6 - EVP_DecryptInit should call EVP_CipherInit() instead of EVP_CipherInit_ex(), to get the right behavior when passed uninitialized context structures (#83766) - build with -mcpu=ev5 on alpha family (#83828)
Wed Jan 22 23:00:00 2003 Tim Powers - rebuilt
Fri Jan 17 23:00:00 2003 Phil Knirsch 0.9.7-4 - Added IBM hw crypto support patch.
Wed Jan 15 23:00:00 2003 Nalin Dahyabhai - add missing builddep on sed
Thu Jan 9 23:00:00 2003 Bill Nottingham 0.9.7-3 - debloat - fix broken manpage symlinks
Wed Jan 8 23:00:00 2003 Nalin Dahyabhai 0.9.7-2 - fix double-free in \'openssl ca\'
Fri Jan 3 23:00:00 2003 Nalin Dahyabhai 0.9.7-1 - update to 0.9.7 final
Tue Dec 17 23:00:00 2002 Nalin Dahyabhai 0.9.7-0 - update to 0.9.7 beta6 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
Wed Dec 11 23:00:00 2002 Nalin Dahyabhai - update to 0.9.7 beta5 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
Wed Oct 23 00:00:00 2002 Nalin Dahyabhai 0.9.6b-30 - add configuration stanza for x86_64 and use it on x86_64 - build for linux-ppc on ppc - start running the self-tests again
Thu Oct 3 00:00:00 2002 Elliot Lee 0.9.6b-29hammer.3 - Merge fixes from previous hammer packages, including general x86-64 and multilib
Wed Aug 7 00:00:00 2002 Nalin Dahyabhai 0.9.6b-29 - rebuild
Fri Aug 2 00:00:00 2002 Nalin Dahyabhai 0.9.6b-28 - update asn patch to fix accidental reversal of a logic check
Thu Aug 1 00:00:00 2002 Nalin Dahyabhai 0.9.6b-27 - update asn patch to reduce chance that compiler optimization will remove one of the added tests
Thu Aug 1 00:00:00 2002 Nalin Dahyabhai 0.9.6b-26 - rebuild
Tue Jul 30 00:00:00 2002 Nalin Dahyabhai 0.9.6b-25 - add patch to fix ASN.1 vulnerabilities
Fri Jul 26 00:00:00 2002 Nalin Dahyabhai 0.9.6b-24 - add backport of Ben Laurie\'s patches for OpenSSL 0.9.6d
Thu Jul 18 00:00:00 2002 Nalin Dahyabhai 0.9.6b-23 - own /usr/share/ssl/misc
Sat Jun 22 00:00:00 2002 Tim Powers - automated rebuild
Mon May 27 00:00:00 2002 Tim Powers - automated rebuild
Sat May 18 00:00:00 2002 Nalin Dahyabhai 0.9.6b-20 - free ride through the build system (whee!)
Fri May 17 00:00:00 2002 Nalin Dahyabhai 0.9.6b-19 - rebuild in new environment
Fri Apr 5 00:00:00 2002 Nalin Dahyabhai 0.9.6b-17, 0.9.6b-18 - merge RHL-specific bits into stronghold package, rename
Wed Apr 3 00:00:00 2002 Gary Benson stronghold-0.9.6c-2 - add support for Chrysalis Luna token
Tue Mar 26 23:00:00 2002 Gary Benson - disable AEP random number generation, other AEP fixes
Fri Mar 15 23:00:00 2002 Nalin Dahyabhai 0.9.6b-15 - only build subpackages on primary arches
Thu Mar 14 23:00:00 2002 Nalin Dahyabhai 0.9.6b-13 - on ia32, only disable use of assembler on i386 - enable assembly on ia64
Mon Jan 7 23:00:00 2002 Florian La Roche 0.9.6b-11 - fix sparcv9 entry
Mon Jan 7 23:00:00 2002 Gary Benson stronghold-0.9.6c-1 - upgrade to 0.9.6c - bump BuildArch to i686 and enable assembler on all platforms - synchronise with shrimpy and rawhide - bump soversion to 3
Thu Oct 11 00:00:00 2001 Florian La Roche - delete BN_LLONG for s390x, patch from Oliver Paukstadt
Tue Sep 18 00:00:00 2001 Nalin Dahyabhai 0.9.6b-9 - update AEP driver patch
Tue Sep 11 00:00:00 2001 Nalin Dahyabhai - adjust RNG disabling patch to match version of patch from Broadcom
Sat Sep 8 00:00:00 2001 Nalin Dahyabhai 0.9.6b-8 - disable the RNG in the ubsec engine driver
Wed Aug 29 00:00:00 2001 Nalin Dahyabhai 0.9.6b-7 - tweaks to the ubsec engine driver
Sat Aug 25 00:00:00 2001 Nalin Dahyabhai 0.9.6b-6 - tweaks to the ubsec engine driver
Fri Aug 24 00:00:00 2001 Nalin Dahyabhai 0.9.6b-5 - update ubsec engine driver from Broadcom
Sat Aug 11 00:00:00 2001 Nalin Dahyabhai 0.9.6b-4 - move man pages back to %{_mandir}/man?/foo.?ssl from %{_mandir}/man?ssl/foo.? - add an [ engine ] section to the default configuration file
Fri Aug 10 00:00:00 2001 Nalin Dahyabhai - add a patch for selecting a default engine in SSL_library_init()
Tue Jul 24 00:00:00 2001 Nalin Dahyabhai 0.9.6b-3 - add patches for AEP hardware support - add patch to keep trying when we fail to load a cert from a file and there are more in the file - add missing prototype for ENGINE_ubsec() in engine_int.h
Thu Jul 19 00:00:00 2001 Nalin Dahyabhai 0.9.6b-2 - actually add hw_ubsec to the engine list
Wed Jul 18 00:00:00 2001 Nalin Dahyabhai - add in the hw_ubsec driver from CVS
Thu Jul 12 00:00:00 2001 Nalin Dahyabhai 0.9.6b-1 - update to 0.9.6b
Fri Jul 6 00:00:00 2001 Nalin Dahyabhai - move .so symlinks back to %{_libdir}
Wed Jul 4 00:00:00 2001 Nalin Dahyabhai - move shared libraries to /lib (#38410)
Tue Jun 26 00:00:00 2001 Nalin Dahyabhai - switch to engine code base
Tue Jun 19 00:00:00 2001 Nalin Dahyabhai - add a script for creating dummy certificates - move man pages from %{_mandir}/man?/foo.?ssl to %{_mandir}/man?ssl/foo.?
Fri Jun 8 00:00:00 2001 Florian La Roche - add s390x support
Sat Jun 2 00:00:00 2001 Nalin Dahyabhai - change two memcpy() calls to memmove() - don\'t define L_ENDIAN on alpha
Thu May 24 00:00:00 2001 Joe Orton stronghold-0.9.6a-1 - Add \'stronghold-\' prefix to package names. - Obsolete standard openssl packages.
Thu May 17 00:00:00 2001 Joe Orton - Add BuildArch: i586 as per Nalin\'s advice.
Wed May 16 00:00:00 2001 Joe Orton - Enable assembler on ix86 (using new .tar.bz2 which does include the asm directories).
Wed May 16 00:00:00 2001 Nalin Dahyabhai - make subpackages depend on the main package
Wed May 2 00:00:00 2001 Nalin Dahyabhai - adjust the hobble script to not disturb symlinks in include/ (fix from Joe Orton)
Fri Apr 27 00:00:00 2001 Nalin Dahyabhai - drop the m2crypo patch we weren\'t using
Wed Apr 25 00:00:00 2001 Nalin Dahyabhai - configure using \"shared\" as well
Mon Apr 9 00:00:00 2001 Nalin Dahyabhai - update to 0.9.6a - use the build-shared target to build shared libraries - bump the soversion to 2 because we\'re no longer compatible with our 0.9.5a packages or our 0.9.6 packages - drop the patch for making rsatest a no-op when rsa null support is used - put all man pages into ssl instead of - break the m2crypto modules into a separate package
Tue Mar 13 23:00:00 2001 Nalin Dahyabhai - use BN_LLONG on s390
Mon Mar 12 23:00:00 2001 Nalin Dahyabhai - fix the s390 changes for 0.9.6 (isn\'t supposed to be marked as 64-bit)
Sat Mar 3 23:00:00 2001 Nalin Dahyabhai - move c_rehash to the perl subpackage, because it\'s a perl script now
Fri Mar 2 23:00:00 2001 Nalin Dahyabhai - update to 0.9.6 - enable MD2 - use the libcrypto.so and libssl.so targets to build shared libs with - bump the soversion to 1 because we\'re no longer compatible with any of the various 0.9.5a packages circulating around, which provide lib *.so.0
Wed Feb 28 23:00:00 2001 Florian La Roche - change hobble-openssl for disabling MD2 again
Tue Feb 27 23:00:00 2001 Nalin Dahyabhai - re-disable MD2 -- the EVP_MD_CTX structure would grow from 100 to 152 bytes or so, causing EVP_DigestInit() to zero out stack variables in apps built against a version of the library without it
Mon Feb 26 23:00:00 2001 Nalin Dahyabhai - disable some inline assembly, which on x86 is Pentium-specific - re-enable MD2 (see http://www.ietf.org/ietf/IPR/RSA-MD-all)
Thu Feb 8 23:00:00 2001 Florian La Roche - fix s390 patch
Fri Dec 8 23:00:00 2000 Than Ngo - added support s390
Mon Nov 20 23:00:00 2000 Nalin Dahyabhai - remove -Wa, * and -m * compiler flags from the default Configure file (#20656) - add the CA.pl man page to the perl subpackage
Thu Nov 2 23:00:00 2000 Nalin Dahyabhai - always build with -mcpu=ev5 on alpha
Tue Oct 31 23:00:00 2000 Nalin Dahyabhai - add a symlink from cert.pem to ca-bundle.crt
Thu Oct 26 00:00:00 2000 Nalin Dahyabhai - add a ca-bundle file for packages like Samba to reference for CA certificates
Wed Oct 25 00:00:00 2000 Nalin Dahyabhai - remove libcrypto\'s crypt(), which doesn\'t handle md5crypt (#19295)
Tue Oct 3 00:00:00 2000 Nalin Dahyabhai - add unzip as a buildprereq (#17662) - update m2crypto to 0.05-snap4
Wed Sep 27 00:00:00 2000 Bill Nottingham - fix some issues in building when it\'s not installed
Thu Sep 7 00:00:00 2000 Nalin Dahyabhai - make sure the headers we include are the ones we built with (aaaaarrgh!)
Sat Sep 2 00:00:00 2000 Nalin Dahyabhai - add Richard Henderson\'s patch for BN on ia64 - clean up the changelog
Wed Aug 30 00:00:00 2000 Nalin Dahyabhai - fix the building of python modules without openssl-devel already installed
Thu Aug 24 00:00:00 2000 Nalin Dahyabhai - byte-compile python extensions without the build-root - adjust the makefile to not remove temporary files (like .key files when building .csr files) by marking them as .PRECIOUS
Sun Aug 20 00:00:00 2000 Nalin Dahyabhai - break out python extensions into a subpackage
Tue Jul 18 00:00:00 2000 Nalin Dahyabhai - tweak the makefile some more
Wed Jul 12 00:00:00 2000 Nalin Dahyabhai - disable MD2 support
Fri Jul 7 00:00:00 2000 Nalin Dahyabhai - disable MDC2 support
Mon Jul 3 00:00:00 2000 Nalin Dahyabhai - tweak the disabling of RC5, IDEA support - tweak the makefile
Fri Jun 30 00:00:00 2000 Nalin Dahyabhai - strip binaries and libraries - rework certificate makefile to have the right parts for Apache
Thu Jun 29 00:00:00 2000 Nalin Dahyabhai - use %{_perl} instead of /usr/bin/perl - disable alpha until it passes its own test suite
Sat Jun 10 00:00:00 2000 Nalin Dahyabhai - move the passwd.1 man page out of the passwd package\'s way
Sat Jun 3 00:00:00 2000 Nalin Dahyabhai - update to 0.9.5a, modified for U.S. - add perl as a build-time requirement - move certificate makefile to another package - disable RC5, IDEA, RSA support - remove optimizations for now
Wed Mar 1 23:00:00 2000 Florian La Roche - Bero told me to move the Makefile into this package
Wed Mar 1 23:00:00 2000 Florian La Roche - add lib *.so symlinks to link dynamically against shared libs
Tue Feb 29 23:00:00 2000 Florian La Roche - update to 0.9.5 - run ldconfig directly in post/postun - add FAQ
Sat Dec 18 23:00:00 1999 Bernhard Rosenkrdnzer - Fix build on non-x86 platforms
Fri Nov 12 23:00:00 1999 Bernhard Rosenkrdnzer - move /usr/share/ssl/ * from -devel to main package
Wed Oct 27 00:00:00 1999 Bernhard Rosenkrdnzer - inital packaging - changes from base: - Move /usr/local/ssl to /usr/share/ssl for FHS compliance - handle RPM_OPT_FLAGS
|
|
|