CVSROOT: /cvs Module name: ports Changes by: [email protected] 2024/06/04 10:33:55
Modified files:
security/openssl/3.1: Makefile distinfo
Log message:
Update to OpenSSL 3.1.6
A use-after-free after SSL_free_buffers() and what feels like the 100th
issue in EVP_PKEY_check*. This time it's DSA's turn to DoS the lib.
In addition there's a new config switch relating to atexit() (need to
look more closely) plus unbounded memory growth in some TLSv1.3 configs
(which I forgot to mention for 3.2.2).
