LibreSSL 4.3.0

The LibreSSL project has announced the release of version 4.3.0, which is now available on OpenBSD mirrors.

This is a development release for the 4.3.x branch, so the developers encourage the community to actively test it. No further API or ABI changes are planned for the 4.3 branch.

A key innovation in this version is support for the post-quantum key exchange method MLKEM768_X25519 in TLS, in accordance with IETF draft-ietf-tls-ecdhe-mlkem. A "off-by-one" error in the X.509 certificate depth check has been fixed, which could have led to overwriting 4 bytes in memory when handling malicious data or when client certificate checks were enabled. The maximum depth is now limited to 32. The issue was discovered by Calif.io in collaboration with Claude and Anthropic Research. proxy server Internal improvements:

Obsolete code fragments remaining from SSLv2 and SSLv3/TLS 1.0 support have been removed.

  • ec_point_cmp() has been rewritten.
  • A fast path for well-known DH primes, including those from RFC 7919, has been added to DH_check().
  • Compatibility changes:

Numerous unused macros BN_* with uninformative names (BN_LONG, BN_BITS4, BN_MASK2, etc.) have been removed.

  • The openssl(1) cms command no longer accepts unsupported keys -compress and -uncompress.
  • A PKCS7_NO_DUAL_CONTENT flag has been added for compatible behavior with some language bindings.
  • Memory leaks in CMS_EncryptedData_encrypt() and nref_nos() have been fixed.

Bug fixes:

  • Bit string encoding with trailing zeroes has been corrected.
  • A crash while parsing PKCS#12 and timestamp responses has been resolved.
  • Numerous bugs in libtls (length checks, consistency of error messages) have been fixed.
  • Support for the RSASSA-PSS algorithm with OID has been added to libssl.

Miscellaneous:

  • Functions X509_VERIFY_PARAM_set_hostflags() and SSL_SESSION_dup() have been added to the public API.
  • BIGNUM now uses standard C99 types (uint64_t/uint32_t), resolving issues on 64-bit Windows.
  • Firefox release 150 has resolved 359 vulnerabilities.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster