| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent a7c4fab commit b3afedf
118 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -7,6 +7,51 @@ | |||
| 7 | 7 | https://github.com/openssl/openssl/commits/ and pick the appropriate | |
| 8 | 8 | release branch. | |
| 9 | 9 | ||
| 10 | + Changes between 1.0.2m and 1.0.2n [7 Dec 2017] | ||
| 11 | + | ||
| 12 | + *) Read/write after SSL object in error state | ||
| 13 | + | ||
| 14 | + OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" | ||
| 15 | + mechanism. The intent was that if a fatal error occurred during a handshake | ||
| 16 | + then OpenSSL would move into the error state and would immediately fail if | ||
| 17 | + you attempted to continue the handshake. This works as designed for the | ||
| 18 | + explicit handshake functions (SSL_do_handshake(), SSL_accept() and | ||
| 19 | + SSL_connect()), however due to a bug it does not work correctly if | ||
| 20 | + SSL_read() or SSL_write() is called directly. In that scenario, if the | ||
| 21 | + handshake fails then a fatal error will be returned in the initial function | ||
| 22 | + call. If SSL_read()/SSL_write() is subsequently called by the application | ||
| 23 | + for the same SSL object then it will succeed and the data is passed without | ||
| 24 | + being decrypted/encrypted directly from the SSL/TLS record layer. | ||
| 25 | + | ||
| 26 | + In order to exploit this issue an application bug would have to be present | ||
| 27 | + that resulted in a call to SSL_read()/SSL_write() being issued after having | ||
| 28 | + already received a fatal error. | ||
| 29 | + | ||
| 30 | + This issue was reported to OpenSSL by David Benjamin (Google). | ||
| 31 | + (CVE-2017-3737) | ||
| 32 | + [Matt Caswell] | ||
| 33 | + | ||
| 34 | + *) rsaz_1024_mul_avx2 overflow bug on x86_64 | ||
| 35 | + | ||
| 36 | + There is an overflow bug in the AVX2 Montgomery multiplication procedure | ||
| 37 | + used in exponentiation with 1024-bit moduli. No EC algorithms are affected. | ||
| 38 | + Analysis suggests that attacks against RSA and DSA as a result of this | ||
| 39 | + defect would be very difficult to perform and are not believed likely. | ||
| 40 | + Attacks against DH1024 are considered just feasible, because most of the | ||
| 41 | + work necessary to deduce information about a private key may be performed | ||
| 42 | + offline. The amount of resources required for such an attack would be | ||
| 43 | + significant. However, for an attack on TLS to be meaningful, the server | ||
| 44 | + would have to share the DH1024 private key among multiple clients, which is | ||
| 45 | + no longer an option since CVE-2016-0701. | ||
| 46 | + | ||
| 47 | + This only affects processors that support the AVX2 but not ADX extensions | ||
| 48 | + like Intel Haswell (4th generation). | ||
| 49 | + | ||
| 50 | + This issue was reported to OpenSSL by David Benjamin (Google). The issue | ||
| 51 | + was originally found via the OSS-Fuzz project. | ||
| 52 | + (CVE-2017-3738) | ||
| 53 | + [Andy Polyakov] | ||
| 54 | + | ||
| 10 | 55 | Changes between 1.0.2l and 1.0.2m [2 Nov 2017] | |
| 11 | 56 | ||
| 12 | 57 | *) bn_sqrx8x_internal carry bug on x86_64 | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -592,9 +592,9 @@ my %table=( | |||
| 592 | 592 | "debug-VC-WIN64A","cl:-W3 -Gs0 -Gy -Zi -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -DUNICODE -D_UNICODE -D_CRT_SECURE_NO_DEPRECATE:::WIN64A::SIXTY_FOUR_BIT RC4_CHUNK_LL DES_INT EXPORT_VAR_AS_FN:".eval{my $asm=$x86_64_asm;$asm=~s/x86_64-gcc\.o/bn_asm.o/;$asm}.":auto:win32", | |
| 593 | 593 | # x86 Win32 target defaults to ANSI API, if you want UNICODE, complement | |
| 594 | 594 | # 'perl Configure VC-WIN32' with '-DUNICODE -D_UNICODE' | |
| 595 | - "VC-WIN32","cl:-W3 -Gs0 -GF -Gy -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -D_CRT_SECURE_NO_DEPRECATE:::WIN32::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${x86_asm}:win32n:win32", | ||
| 595 | + "VC-WIN32","cl:-W3 -WX -Gs0 -GF -Gy -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -D_CRT_SECURE_NO_DEPRECATE -D_WINSOCK_DEPRECATED_NO_WARNINGS:::WIN32::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${x86_asm}:win32n:win32", | ||
| 596 | 596 | # Unified CE target | |
| 597 | - "debug-VC-WIN32","cl:-W3 -Gs0 -GF -Gy -Zi -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -D_CRT_SECURE_NO_DEPRECATE:::WIN32::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${x86_asm}:win32n:win32", | ||
| 597 | + "debug-VC-WIN32","cl:-W3 -WX -Gs0 -GF -Gy -Zi -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -D_CRT_SECURE_NO_DEPRECATE -D_WINSOCK_DEPRECATED_NO_WARNINGS:::WIN32::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${x86_asm}:win32n:win32", | ||
| 598 | 598 | "VC-CE","cl::::WINCE::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${no_asm}:win32", | |
| 599 | 599 | ||
| 600 | 600 | # Borland C++ 4.5 | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -4,7 +4,7 @@ | |||
| 4 | 4 | ## Makefile for OpenSSL | |
| 5 | 5 | ## | |
| 6 | 6 | ||
| 7 | - VERSION=1.0.2m | ||
| 7 | + VERSION=1.0.2n | ||
| 8 | 8 | MAJOR=1 | |
| 9 | 9 | MINOR=0.2 | |
| 10 | 10 | SHLIB_VERSION_NUMBER=1.0.0 | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -4,7 +4,7 @@ | |||
| 4 | 4 | ## Makefile for OpenSSL | |
| 5 | 5 | ## | |
| 6 | 6 | ||
| 7 | - VERSION=1.0.2m | ||
| 7 | + VERSION=1.0.2n | ||
| 8 | 8 | MAJOR=1 | |
| 9 | 9 | MINOR=0.2 | |
| 10 | 10 | SHLIB_VERSION_NUMBER=1.0.0 | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -5,6 +5,11 @@ | |||
| 5 | 5 | This file gives a brief overview of the major changes between each OpenSSL | |
| 6 | 6 | release. For more details please read the CHANGES file. | |
| 7 | 7 | ||
| 8 | + Major changes between OpenSSL 1.0.2m and OpenSSL 1.0.2n [7 Dec 2017] | ||
| 9 | + | ||
| 10 | + o Read/write after SSL object in error state (CVE-2017-3737) | ||
| 11 | + o rsaz_1024_mul_avx2 overflow bug on x86_64 (CVE-2017-3738) | ||
| 12 | + | ||
| 8 | 13 | Major changes between OpenSSL 1.0.2l and OpenSSL 1.0.2m [2 Nov 2017] | |
| 9 | 14 | ||
| 10 | 15 | o bn_sqrx8x_internal carry bug on x86_64 (CVE-2017-3736) | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,5 +1,5 @@ | |||
| 1 | 1 | ||
| 2 | - OpenSSL 1.0.2m 2 Nov 2017 | ||
| 2 | + OpenSSL 1.0.2n 7 Dec 2017 | ||
| 3 | 3 | ||
| 4 | 4 | Copyright (c) 1998-2015 The OpenSSL Project | |
| 5 | 5 | Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -124,16 +124,7 @@ int app_RAND_load_file(const char *file, BIO *bio_e, int dont_warn) | |||
| 124 | 124 | char buffer[200]; | |
| 125 | 125 | ||
| 126 | 126 | #ifdef OPENSSL_SYS_WINDOWS | |
| 127 | - /* | ||
| 128 | - * allocate 2 to dont_warn not to use RAND_screen() via | ||
| 129 | - * -no_rand_screen option in s_client | ||
| 130 | - */ | ||
| 131 | - if (dont_warn != 2) { | ||
| 132 | - BIO_printf(bio_e, "Loading 'screen' into random state -"); | ||
| 133 | - BIO_flush(bio_e); | ||
| 134 | - RAND_screen(); | ||
| 135 | - BIO_printf(bio_e, " done\n"); | ||
| 136 | - } | ||
| 127 | + RAND_screen(); | ||
| 137 | 128 | #endif | |
| 138 | 129 | ||
| 139 | 130 | if (file == NULL) | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -148,6 +148,10 @@ | |||
| 148 | 148 | #ifdef _WIN32 | |
| 149 | 149 | static int WIN32_rename(const char *from, const char *to); | |
| 150 | 150 | # define rename(from,to) WIN32_rename((from),(to)) | |
| 151 | + # ifdef fileno | ||
| 152 | + # undef fileno | ||
| 153 | + # endif | ||
| 154 | + # define fileno(a) (int)_fileno(a) | ||
| 151 | 155 | #endif | |
| 152 | 156 | ||
| 153 | 157 | typedef struct { | |
@@ -2788,13 +2792,13 @@ unsigned char *next_protos_parse(unsigned short *outlen, const char *in) | |||
| 2788 | 2792 | OPENSSL_free(out); | |
| 2789 | 2793 | return NULL; | |
| 2790 | 2794 | } | |
| 2791 | - out[start] = i - start; | ||
| 2795 | + out[start] = (unsigned char)(i - start); | ||
| 2792 | 2796 | start = i + 1; | |
| 2793 | 2797 | } else | |
| 2794 | 2798 | out[i + 1] = in[i]; | |
| 2795 | 2799 | } | |
| 2796 | 2800 | ||
| 2797 | - *outlen = len + 1; | ||
| 2801 | + *outlen = (unsigned char)(len + 1); | ||
| 2798 | 2802 | return out; | |
| 2799 | 2803 | } | |
| 2800 | 2804 | #endif /* ndef OPENSSL_NO_TLSEXT */ | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -327,6 +327,9 @@ int MAIN(int argc, char **argv) | |||
| 327 | 327 | } else if (outformat == FORMAT_MSBLOB || outformat == FORMAT_PVK) { | |
| 328 | 328 | EVP_PKEY *pk; | |
| 329 | 329 | pk = EVP_PKEY_new(); | |
| 330 | + if (pk == NULL) | ||
| 331 | + goto end; | ||
| 332 | + | ||
| 330 | 333 | EVP_PKEY_set1_DSA(pk, dsa); | |
| 331 | 334 | if (outformat == FORMAT_PVK) | |
| 332 | 335 | i = i2b_PVK_bio(out, pk, pvk_encr, 0, passout); | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -180,13 +180,6 @@ typedef unsigned int u_int; | |||
| 180 | 180 | # include <fcntl.h> | |
| 181 | 181 | #endif | |
| 182 | 182 | ||
| 183 | - /* Use Windows API with STD_INPUT_HANDLE when checking for input? | ||
| 184 | - Don't look at OPENSSL_SYS_MSDOS for this, since it is always defined if | ||
| 185 | - OPENSSL_SYS_WINDOWS is defined */ | ||
| 186 | - #if defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_WINCE) && defined(STD_INPUT_HANDLE) | ||
| 187 | - #define OPENSSL_USE_STD_INPUT_HANDLE | ||
| 188 | - #endif | ||
| 189 | - | ||
| 190 | 183 | #undef PROG | |
| 191 | 184 | #define PROG s_client_main | |
| 192 | 185 | ||
@@ -236,7 +229,6 @@ static BIO *bio_c_msg = NULL; | |||
| 236 | 229 | static int c_quiet = 0; | |
| 237 | 230 | static int c_ign_eof = 0; | |
| 238 | 231 | static int c_brief = 0; | |
| 239 | - static int c_no_rand_screen = 0; | ||
| 240 | 232 | ||
| 241 | 233 | #ifndef OPENSSL_NO_PSK | |
| 242 | 234 | /* Default PSK identity and key */ | |
@@ -452,10 +444,6 @@ static void sc_usage(void) | |||
| 452 | 444 | " -keymatexport label - Export keying material using label\n"); | |
| 453 | 445 | BIO_printf(bio_err, | |
| 454 | 446 | " -keymatexportlen len - Export len bytes of keying material (default 20)\n"); | |
| 455 | - #ifdef OPENSSL_SYS_WINDOWS | ||
| 456 | - BIO_printf(bio_err, | ||
| 457 | - " -no_rand_screen - Do not use RAND_screen() to initialize random state\n"); | ||
| 458 | - #endif | ||
| 459 | 447 | } | |
| 460 | 448 | ||
| 461 | 449 | #ifndef OPENSSL_NO_TLSEXT | |
@@ -642,10 +630,11 @@ static int serverinfo_cli_parse_cb(SSL *s, unsigned int ext_type, | |||
| 642 | 630 | unsigned char ext_buf[4 + 65536]; | |
| 643 | 631 | ||
| 644 | 632 | /* Reconstruct the type/len fields prior to extension data */ | |
| 645 | - ext_buf[0] = ext_type >> 8; | ||
| 646 | - ext_buf[1] = ext_type & 0xFF; | ||
| 647 | - ext_buf[2] = inlen >> 8; | ||
| 648 | - ext_buf[3] = inlen & 0xFF; | ||
| 633 | + inlen &= 0xffff; /* for formal memcpy correctness */ | ||
| 634 | + ext_buf[0] = (unsigned char)(ext_type >> 8); | ||
| 635 | + ext_buf[1] = (unsigned char)(ext_type); | ||
| 636 | + ext_buf[2] = (unsigned char)(inlen >> 8); | ||
| 637 | + ext_buf[3] = (unsigned char)(inlen); | ||
| 649 | 638 | memcpy(ext_buf + 4, in, inlen); | |
| 650 | 639 | ||
| 651 | 640 | BIO_snprintf(pem_name, sizeof(pem_name), "SERVERINFO FOR EXTENSION %d", | |
@@ -1148,10 +1137,6 @@ int MAIN(int argc, char **argv) | |||
| 1148 | 1137 | keymatexportlen = atoi(*(++argv)); | |
| 1149 | 1138 | if (keymatexportlen == 0) | |
| 1150 | 1139 | goto bad; | |
| 1151 | - #ifdef OPENSSL_SYS_WINDOWS | ||
| 1152 | - } else if (strcmp(*argv, "-no_rand_screen") == 0) { | ||
| 1153 | - c_no_rand_screen = 1; | ||
| 1154 | - #endif | ||
| 1155 | 1140 | } else { | |
| 1156 | 1141 | BIO_printf(bio_err, "unknown option %s\n", *argv); | |
| 1157 | 1142 | badop = 1; | |
@@ -1268,7 +1253,7 @@ int MAIN(int argc, char **argv) | |||
| 1268 | 1253 | if (!load_excert(&exc, bio_err)) | |
| 1269 | 1254 | goto end; | |
| 1270 | 1255 | ||
| 1271 | - if (!app_RAND_load_file(NULL, bio_err, ++c_no_rand_screen) && inrand == NULL | ||
| 1256 | + if (!app_RAND_load_file(NULL, bio_err, 1) && inrand == NULL | ||
| 1272 | 1257 | && !RAND_status()) { | |
| 1273 | 1258 | BIO_printf(bio_err, | |
| 1274 | 1259 | "warning, not much extra random data, consider using the -rand option\n"); | |
@@ -1808,16 +1793,17 @@ int MAIN(int argc, char **argv) | |||
| 1808 | 1793 | tv.tv_usec = 0; | |
| 1809 | 1794 | i = select(width, (void *)&readfds, (void *)&writefds, | |
| 1810 | 1795 | NULL, &tv); | |
| 1811 | - #if defined(OPENSSL_USE_STD_INPUT_HANDLE) | ||
| 1796 | + # if defined(OPENSSL_SYS_WINCE) || defined(OPENSSL_SYS_MSDOS) | ||
| 1797 | + if (!i && (!_kbhit() || !read_tty)) | ||
| 1798 | + continue; | ||
| 1799 | + # else | ||
| 1812 | 1800 | if (!i && (!((_kbhit()) | |
| 1813 | 1801 | || (WAIT_OBJECT_0 == | |
| 1814 | 1802 | WaitForSingleObject(GetStdHandle | |
| 1815 | 1803 | (STD_INPUT_HANDLE), | |
| 1816 | 1804 | 0))) | |
| 1817 | 1805 | || !read_tty)) | |
| 1818 | 1806 | continue; | |
| 1819 | - #else | ||
| 1820 | - if(!i && (!_kbhit() || !read_tty) ) continue; | ||
| 1821 | 1807 | # endif | |
| 1822 | 1808 | } else | |
| 1823 | 1809 | i = select(width, (void *)&readfds, (void *)&writefds, | |
@@ -2019,12 +2005,12 @@ int MAIN(int argc, char **argv) | |||
| 2019 | 2005 | } | |
| 2020 | 2006 | } | |
| 2021 | 2007 | #if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) | |
| 2022 | - #if defined(OPENSSL_USE_STD_INPUT_HANDLE) | ||
| 2008 | + # if defined(OPENSSL_SYS_WINCE) || defined(OPENSSL_SYS_MSDOS) | ||
| 2009 | + else if (_kbhit()) | ||
| 2010 | + # else | ||
| 2023 | 2011 | else if ((_kbhit()) | |
| 2024 | 2012 | || (WAIT_OBJECT_0 == | |
| 2025 | 2013 | WaitForSingleObject(GetStdHandle(STD_INPUT_HANDLE), 0))) | |
| 2026 | - #else | ||
| 2027 | - else if (_kbhit()) | ||
| 2028 | 2014 | # endif | |
| 2029 | 2015 | #elif defined (OPENSSL_SYS_NETWARE) | |
| 2030 | 2016 | else if (_kbhit()) | |
| Back | FazBrowse Home | New Git URL |
0 commit comments