Mark J. Cox 951dfbb13a Introduce limits to prevent malicious keys being able to
cause a denial of service.  (CVE-2006-2940)
[Steve Henson, Bodo Moeller]

Fix ASN.1 parsing of certain invalid structures that can result
in a denial of service.  (CVE-2006-2937)  [Steve Henson]

Fix buffer overflow in SSL_get_shared_ciphers() function.
(CVE-2006-3738) [Tavis Ormandy and Will Drewry, Google Security Team]

Fix SSL client code which could crash if connecting to a
malicious SSLv2 server.  (CVE-2006-4343)
[Tavis Ormandy and Will Drewry, Google Security Team]
2006-09-28 11:29:03 +00:00
..
2005-03-31 13:57:54 +00:00
2006-02-21 01:00:47 +00:00
2005-03-30 10:26:02 +00:00
2005-03-31 10:55:55 +00:00
2005-05-17 16:50:46 +00:00
2004-12-12 13:15:49 +00:00
2006-01-03 14:20:47 +00:00
2006-02-19 13:45:22 +00:00
2005-04-23 13:45:49 +00:00
2004-03-27 13:30:14 +00:00
2005-05-16 10:11:04 +00:00
2005-05-16 10:11:04 +00:00
2005-05-16 10:11:04 +00:00
2005-05-16 10:11:04 +00:00
2006-05-04 12:15:59 +00:00
2005-05-11 03:45:39 +00:00
2006-04-15 13:17:53 +00:00
2005-07-16 11:13:10 +00:00
2005-07-16 11:13:10 +00:00
2005-05-16 10:11:04 +00:00
2004-04-25 12:46:39 +00:00
2005-07-26 12:46:53 +00:00
2004-04-25 12:46:39 +00:00
2001-07-27 02:22:42 +00:00
2001-07-27 02:22:42 +00:00
2001-07-27 02:22:42 +00:00
2005-05-11 03:45:39 +00:00
2005-07-16 11:13:10 +00:00
2006-09-22 17:07:40 +00:00
2002-11-27 13:40:11 +00:00