openssl/crypto/evp
Andy Polyakov 2198b3a55d crypto/evp: harden AEAD ciphers.
Originally a crash in 32-bit build was reported CHACHA20-POLY1305
cipher. The crash is triggered by truncated packet and is result
of excessive hashing to the edge of accessible memory. Since hash
operation is read-only it is not considered to be exploitable
beyond a DoS condition. Other ciphers were hardened.

Thanks to Robert Święcki for report.

CVE-2017-3731

Reviewed-by: Rich Salz <rsalz@openssl.org>
2017-01-26 10:54:01 +00:00
..
bio_b64.c
bio_enc.c
bio_md.c
bio_ok.c
build.info
c_allc.c
c_alld.c
cmeth_lib.c
digest.c
e_aes_cbc_hmac_sha1.c Cleanup EVP_CIPH/EP_CTRL duplicate defines 2017-01-24 18:47:10 +01:00
e_aes_cbc_hmac_sha256.c Cleanup EVP_CIPH/EP_CTRL duplicate defines 2017-01-24 18:47:10 +01:00
e_aes.c crypto/evp: harden AEAD ciphers. 2017-01-26 10:54:01 +00:00
e_bf.c
e_camellia.c
e_cast.c
e_chacha20_poly1305.c crypto/evp: harden AEAD ciphers. 2017-01-26 10:54:01 +00:00
e_des3.c Fix the overlapping check for fragmented "Update" operations 2017-01-25 15:02:44 +00:00
e_des.c
e_idea.c
e_null.c
e_old.c
e_rc2.c
e_rc4_hmac_md5.c crypto/evp: harden RC4_MD5 cipher. 2017-01-26 10:54:01 +00:00
e_rc4.c Cleanup EVP_CIPH/EP_CTRL duplicate defines 2017-01-24 18:47:10 +01:00
e_rc5.c
e_seed.c
e_xcbc_d.c
encode.c
evp_cnf.c
evp_enc.c Remove assert from is_partially_overlapping() 2017-01-25 15:02:45 +00:00
evp_err.c Fix the overlapping check for fragmented "Update" operations 2017-01-25 15:02:44 +00:00
evp_key.c
evp_lib.c Fix EVP_MD_meth_get_flags 2016-12-22 15:23:41 +01:00
evp_locl.h Fix the overlapping check for fragmented "Update" operations 2017-01-25 15:02:44 +00:00
evp_pbe.c
evp_pkey.c
m_md2.c
m_md4.c
m_md5_sha1.c Fix ctrl operation for SHA1/MD5SHA1. 2016-11-25 20:50:58 +00:00
m_md5.c
m_mdc2.c
m_null.c
m_ripemd.c
m_sha1.c Fix ctrl operation for SHA1/MD5SHA1. 2016-11-25 20:50:58 +00:00
m_sigver.c
m_wp.c
names.c
p5_crpt2.c
p5_crpt.c
p_dec.c
p_enc.c
p_lib.c Add support for Poly1305 in EVP_PKEY 2017-01-24 15:40:37 +01:00
p_open.c
p_seal.c
p_sign.c
p_verify.c
pmeth_fn.c Reformat M_check_autoarg to match our coding style 2016-12-20 23:21:25 +01:00
pmeth_gn.c
pmeth_lib.c Add support for Poly1305 in EVP_PKEY 2017-01-24 15:40:37 +01:00
scrypt.c