openssl/crypto
Dr. Stephen Henson f9b6c0ba4c Fix for CVE-2014-0076
Fix for the attack described in the paper "Recovering OpenSSL
ECDSA Nonces Using the FLUSH+RELOAD Cache Side-channel Attack"
by Yuval Yarom and Naomi Benger. Details can be obtained from:
http://eprint.iacr.org/2014/140

Thanks to Yuval Yarom and Naomi Benger for discovering this
flaw and to Yuval Yarom for supplying a fix.
(cherry picked from commit 2198be3483)

Conflicts:

	CHANGES
2014-03-12 14:29:43 +00:00
..
aes aes/asm/vpaes-ppc.pl: fix traceback info. 2014-02-25 20:11:34 +01:00
asn1 make depend 2014-02-19 20:09:08 +00:00
bf
bio bss_dgram.c,d1_lib.c: make it compile with mingw. 2014-03-06 14:04:56 +01:00
bn Fix for CVE-2014-0076 2014-03-12 14:29:43 +00:00
buffer Typo. 2013-07-17 21:45:00 +01:00
camellia x86_64 assembly pack: make Windows build more robust. 2013-01-22 22:27:28 +01:00
cast
cmac fix reset fix 2012-04-11 15:05:07 +00:00
cms make depend 2014-02-19 20:09:08 +00:00
comp
conf New config module for string tables. This can be used to add new 2012-10-22 13:05:54 +00:00
des SPARC T4 assembly pack: treat zero input length in CBC. 2014-03-07 10:30:37 +01:00
dh dh_check.c: check BN_CTX_get's return value. 2014-03-06 14:19:37 +01:00
dsa misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
dso misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
ec Fix for CVE-2014-0076 2014-03-12 14:29:43 +00:00
ecdh make depend 2014-02-19 20:09:08 +00:00
ecdsa make depend 2014-02-19 20:09:08 +00:00
engine make depend 2014-02-19 20:09:08 +00:00
err misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
evp make depend 2014-02-19 20:09:08 +00:00
hmac
idea
jpake
krb5
lhash
md2
md4 Fix some clang warnings. 2013-01-13 21:04:39 +00:00
md5 misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
mdc2
modes make depend 2014-02-19 20:09:08 +00:00
objects CABForum EV OIDs for Subject Jurisdiction of Incorporation or Registration. 2014-02-26 15:33:11 +00:00
ocsp Constification. 2013-10-07 12:45:26 +01:00
pem Fix warning. 2014-02-13 03:11:58 +00:00
perlasm SPARC T4 assembly pack: treat zero input length in CBC. 2014-03-07 10:30:37 +01:00
pkcs7 Add suppot for ASCII with CRLF canonicalisation. 2014-02-13 14:35:56 +00:00
pkcs12 PKCS#8 support for alternative PRFs. 2014-03-01 23:16:08 +00:00
pqueue
rand Avoid Windows 8 Getversion deprecated errors. 2014-02-25 13:40:33 +00:00
rc2 misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
rc4 rc4/asm/rc4-586.pl: allow for 386-only build. 2014-02-27 14:19:19 +01:00
rc5 Update support for Intel compiler: add linux-x86_64-icc and fix problems. 2012-11-28 13:05:13 +00:00
ripemd misspellings fixes by https://github.com/vlajos/misspell_fixer 2013-09-05 21:39:42 +01:00
rsa make depend 2014-02-19 20:09:08 +00:00
seed
sha sha/asm/sha256-586.pl: don't try to compile SIMD with no-sse2. 2014-02-26 10:22:13 +01:00
srp srp/srp_grps.h: make it Compaq C-friendly. 2013-11-12 22:09:55 +01:00
stack CMS support for key agreeement recipient info. 2013-07-17 21:45:00 +01:00
store
threads
ts Rename Suite B functions for consistency. 2012-08-03 15:58:15 +00:00
txt_db
ui
whrlpool x86_64 assembly pack: make Windows build more robust. 2013-01-22 22:27:28 +01:00
x509 For self signed root only indicate one error. 2014-03-03 23:36:46 +00:00
x509v3 Don't use BN_ULLONG in n2l8 use SCTS_TIMESTAMP. 2014-02-25 15:06:51 +00:00
.cvsignore
alphacpuid.pl
arm_arch.h
armcap.c crypto/armcap.c: fix typo in rdtsc subroutine. 2013-09-15 22:07:49 +02:00
armv4cpuid.S
c64xpluscpuid.pl C64x+ assembly pack: improve EABI support. 2012-11-28 13:19:10 +00:00
cpt_err.c
cryptlib.c Avoid Windows 8 Getversion deprecated errors. 2014-02-25 13:40:33 +00:00
cryptlib.h
crypto-lib.com Move CT viewer extension code to crypto/x509v3 2014-02-20 18:48:56 +00:00
crypto.h Move gmtime functions to crypto.h. 2014-02-19 18:02:04 +00:00
cversion.c
ebcdic.c
ebcdic.h
ex_data.c
fips_err.h
fips_ers.c
ia64cpuid.S
install-crypto.com
lock.c
LPdir_nyi.c
LPdir_unix.c
LPdir_vms.c
LPdir_win.c
LPdir_win32.c
LPdir_wince.c
Makefile make depend 2014-02-19 20:09:08 +00:00
md32_common.h Initial aarch64 bits. 2013-10-13 19:15:15 +02:00
mem.c Version skew reduction: trivia (I hope). 2012-06-03 22:00:21 +00:00
mem_clr.c
mem_dbg.c
o_dir.c
o_dir.h
o_dir_test.c
o_fips.c
o_init.c remove unnecessary attempt to automatically call OPENSSL_init 2012-07-01 22:25:04 +00:00
o_str.c Improve WINCE support. 2013-01-19 21:23:13 +01:00
o_str.h
o_time.c Move gmtime functions to crypto.h. 2014-02-19 18:02:04 +00:00
opensslconf.h.in
opensslv.h
ossl_typ.h Add KDF for DH. 2013-08-05 15:45:01 +01:00
pariscid.pl PA-RISC assembler pack: switch to bve in 64-bit builds. 2013-06-18 10:37:00 +02:00
ppccap.c ppc64-mont.pl: eliminate dependency on GPRs' upper halves. 2013-11-27 22:50:00 +01:00
ppccpuid.pl PPC assembly pack: add .size directives. 2013-10-15 00:14:39 +02:00
s390xcap.c
s390xcpuid.S
sparc_arch.h Support for SPARC T4 MONT[MUL|SQR] instructions. 2012-11-17 10:34:11 +00:00
sparccpuid.S sparccpuid.S: work around emulator bug on T1. 2013-02-11 10:39:50 +01:00
sparcv9cap.c sparcv9cap.c: omit random detection. 2013-12-28 13:31:14 +01:00
symhacks.h Add callbacks supporting generation and retrieval of supplemental data entries, facilitating RFC 5878 (TLS auth extensions) 2013-09-06 13:59:13 +01:00
thr_id.c Fix warning. 2012-09-17 17:21:58 +00:00
uid.c
vms_rms.h
x86_64cpuid.pl x86[_64]cpuid.pl: add low-level RDSEED. 2014-02-14 17:24:12 +01:00
x86cpuid.pl x86[_64]cpuid.pl: add low-level RDSEED. 2014-02-14 17:24:12 +01:00