CVSROOT: /cvs
Module name: ports
Changes by: [email protected] 2026/08/05 10:36:29
Modified files:
security/openssl/4.0: Makefile
Added files:
security/openssl/4.0/patches: patch-crypto_x509_x509_vfy_c
Log message:
openssl/4.0: plug client-side memleak
Free bs when the OCSP basic response contains no single responses.
I have no idea why this utterly trivial change needed almost as many lines
of explanatory comment as it took weeks to merge it, plus a CVE on top, but
here we are. My time's already been wasted...
Free BS indeed: https://www.openwall.com/lists/oss-security/2026/08/05/8