pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/security/wolfssl security/wolfssl: Updates to v4.7.0



details:   https://anonhg.NetBSD.org/pkgsrc/rev/00c02bfd5394
branches:  trunk
changeset: 448426:00c02bfd5394
user:      fox <fox%pkgsrc.org@localhost>
date:      Mon Mar 08 03:44:34 2021 +0000

description:
security/wolfssl: Updates to v4.7.0

Changes since v4.6.0:

wolfSSL Release 4.7.0 (February 16, 2021)

Release 4.7.0 of wolfSSL embedded TLS has bug fixes and new features including:
New Feature Additions

  * Compatibility Layer expansion SSL_get_verify_mode, X509_VERIFY_PARAM API,
    X509_STORE_CTX API added
  * WOLFSSL_PSK_IDENTITY_ALERT macro added for enabling a subset of TLS alerts
  * Function wolfSSL_CTX_NoTicketTLSv12 added to enable turning off session
    tickets with TLS 1.2 while keeping TLS 1.3 session tickets available
  * Implement RFC 5705: Keying Material Exporters for TLS
  * Added --enable-reproducible-build flag for making more deterministic
    library outputs to assist debugging
  * Added support for S/MIME (Secure/Multipurpose Internet Mail Extensions)
    bundles

Fixes

  * Fix to free mutex when cert manager is free’d
  * Compatibility layer EVP function to return the correct block size and type
  * DTLS secure renegotiation fixes including resetting timeout and retransmit
    on duplicate HelloRequest
  * Fix for edge case with shrink buffer and secure renegotiation
  * Compile fix for type used with curve448 and PPC64
  * Fixes for SP math all with PPC64 and other embedded compilers
  * SP math all fix when performing montgomery reduction on one word modulus
  * Fixes to SP math all to better support digit size of 8-bit
  * Fix for results of edge case with SP integer square operation
  * Stop non-ct mod inv from using register x29 with SP ARM64 build
  * Fix edge case when generating z value of ECC with SP code
  * Fixes for PKCS7 with crypto callback (devId) with RSA and RNG
  * Fix for compiling builds with RSA verify and public only
  * Fix for PKCS11 not properly exporting the public key due to a missing key
    type field
  * Call certificate callback with certificate depth issues
  * Fix for out-of-bounds read in TLSX_CSR_Parse()
  * Fix incorrect AES-GCM tag generation in the EVP layer
  * Fix for out of bounds write with SP math all enabled and an edge case of
    calling sp_tohex on the result of sp_mont_norm
  * Fix for parameter check in sp_rand_prime to handle 0 length values
  * Fix for edge case of failing malloc resulting in an out of bounds write
    with SHA256/SHA512 when small stack is enabled

Improvements/Optimizations

  * Added --enable-wolftpm option for easily building wolfSSL to be used with
    wolfTPM
  * DTLS macro WOLFSSL_DTLS_RESEND_ONLY_TIMEOUT added for resending flight
    only after a timeout
  * Update linux kernel module to use kvmalloc and kvfree
  * Add user settings option to cmake build
  * Added support for AES GCM session ticket encryption
  * Thread protection for global RNG used by wolfSSL_RAND_bytes function calls
  * Sanity check on FIPs configure flag used against the version of FIPs
    bundle
  * --enable-aesgcm=table now is compatible with --enable-linuxkm
  * Increase output buffer size that wolfSSL_RAND_bytes can handle
  * Out of directory builds resolved, wolfSSL can now be built in a separate
    directory than the root wolfssl directory

Vulnerabilities

  * [HIGH] CVE-2021-3336: In earlier versions of wolfSSL there exists a
    potential man in the middle attack on TLS 1.3 clients. Malicious
    attackers with a privileged network position can impersonate TLS 1.3
    servers and bypass authentication. Users that have applications with
    client side code and have TLS 1.3 turned on, should update to the latest
    version of wolfSSL. Users that do not have TLS 1.3 turned on, or that are
    server side only, are NOT affected by this report. For the code change
    see #3676. Thanks to Aina Toky Rasoamanana and Olivier Levillain from
    Télécom SudParis for the report.
  * [LOW] In the case of using custom ECC curves there is the potential for a
    crafted compressed ECC key that has a custom prime value to cause a hang
    when imported. This only affects applications that are loading in ECC keys
    with wolfSSL builds that have compressed ECC keys and custom ECC curves
    enabled.
  * [LOW] With TLS 1.3 authenticated-only ciphers a section of the server
    hello could contain 16 bytes of uninitialized data when sent to the
    connected peer. This affects only a specific build of wolfSSL with TLS
    1.3 early data enabled and using authenticated-only ciphers with TLS 1.3.

For additional vulnerability information visit the vulnerability page at
https://www.wolfssl.com/docs/security-vulnerabilities/

See INSTALL file for build instructions.
More info can be found on-line at https://wolfssl.com/wolfSSL/Docs.html

diffstat:

 security/wolfssl/Makefile |   4 ++--
 security/wolfssl/distinfo |  10 +++++-----
 2 files changed, 7 insertions(+), 7 deletions(-)

diffs (28 lines):

diff -r 454f0806d674 -r 00c02bfd5394 security/wolfssl/Makefile
--- a/security/wolfssl/Makefile Mon Mar 08 00:08:16 2021 +0000
+++ b/security/wolfssl/Makefile Mon Mar 08 03:44:34 2021 +0000
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.5 2020/12/28 16:40:54 fox Exp $
+# $NetBSD: Makefile,v 1.6 2021/03/08 03:44:34 fox Exp $
 
-DISTNAME=      wolfssl-4.6.0
+DISTNAME=      wolfssl-4.7.0
 CATEGORIES=    security
 MASTER_SITES=  https://www.wolfssl.com/
 EXTRACT_SUFX=  .zip
diff -r 454f0806d674 -r 00c02bfd5394 security/wolfssl/distinfo
--- a/security/wolfssl/distinfo Mon Mar 08 00:08:16 2021 +0000
+++ b/security/wolfssl/distinfo Mon Mar 08 03:44:34 2021 +0000
@@ -1,7 +1,7 @@
-$NetBSD: distinfo,v 1.4 2020/12/28 16:40:54 fox Exp $
+$NetBSD: distinfo,v 1.5 2021/03/08 03:44:34 fox Exp $
 
-SHA1 (wolfssl-4.6.0.zip) = 3c2a423081e575cf730643c1c4cdae25c6697832
-RMD160 (wolfssl-4.6.0.zip) = 77a7bfe5b000ef6b444d1074c8650861f766c41f
-SHA512 (wolfssl-4.6.0.zip) = 23408199baf5721a75d616effe8d3001e711ddd1728ab83270b594fec4e1446fa8f2c428fd5733c9edb6172a4ff64479ca8e61922645914c0685b08c3aeeac93
-Size (wolfssl-4.6.0.zip) = 9071773 bytes
+SHA1 (wolfssl-4.7.0.zip) = 1b714a990ad6ebb1d94bf874a2f65c73a6b0eb72
+RMD160 (wolfssl-4.7.0.zip) = f448fad0ba1abe7b6baf1b9e83aeaa67c25d4bcc
+SHA512 (wolfssl-4.7.0.zip) = b003af8db75677b448379f16219dc59c32b39998aa1b25a46ff53d476f48e901dc4fe5b0a36a0fec025a7a1228a88b7472276dc0938133d85c81a61f07394a8a
+Size (wolfssl-4.7.0.zip) = 9121149 bytes
 SHA1 (patch-certs_intermediate_genintcerts.sh) = bdcf9a1fd14170aaf780ab9677fd8bc6e4ddc75c


Home | Main Index | Thread Index | Old Index