提交 c56f5b8e 编写于 作者: D Dr. Stephen Henson

Always return errors in ssl3_get_client_hello

If we successfully match a cookie don't set return value to 2 as this
results in other error conditions returning 2 as well.

Instead set return value to -2 which can be checked later if everything
else is OK.
上级 c6913eeb
......@@ -1082,8 +1082,8 @@ int ssl3_get_client_hello(SSL *s)
SSL_R_COOKIE_MISMATCH);
goto f_err;
}
ret = 2;
/* Set to -2 so if successful we return 2 */
ret = -2;
}
p += cookie_len;
......@@ -1461,7 +1461,7 @@ int ssl3_get_client_hello(SSL *s)
}
}
if (ret < 0) ret=1;
if (ret < 0) ret=-ret;
if (0)
{
f_err:
......@@ -1469,7 +1469,7 @@ f_err:
}
err:
if (ciphers != NULL) sk_SSL_CIPHER_free(ciphers);
return(ret);
return ret < 0 ? -1 : ret;
}
int ssl3_send_server_hello(SSL *s)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册