HomeFreeBSD

openssl: Import OpenSSL 3.0.15.

Description

openssl: Import OpenSSL 3.0.15.

This release incorporates the following bug fixes and mitigations:

  • Fixed possible denial of service in X.509 name checks ([CVE-2024-6119])
  • Fixed possible buffer overread in SSL_select_next_proto() ([CVE-2024-5535])

Release notes can be found at:
https://openssl-library.org/news/openssl-3.0-notes/index.html

Details

Provenance
gordonAuthored on Wed, Sep 4, 3:56 AM
Parents
rGe60dbfd00b00: Avoid type errors in EAI-related name check logic.
Branches
Unknown
Tags
Unknown
References
tag: vendor/openssl/3.0.15, vendor/openssl-3.0