Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
OpenHarmony
Third Party Openssl
提交
206310c3
T
Third Party Openssl
项目概览
OpenHarmony
/
Third Party Openssl
1 年多 前同步成功
通知
10
Star
18
Fork
1
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
T
Third Party Openssl
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
206310c3
编写于
2月 16, 2012
作者:
D
Dr. Stephen Henson
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
Fix bug in CVE-2011-4619: check we have really received a client hello
before rejecting multiple SGC restarts.
上级
58631637
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
14 addition
and
8 deletion
+14
-8
CHANGES
CHANGES
+7
-0
ssl/s3_srvr.c
ssl/s3_srvr.c
+7
-8
未找到文件。
CHANGES
浏览文件 @
206310c3
...
...
@@ -548,6 +548,13 @@
Add command line options to s_client/s_server.
[Steve Henson]
Changes between 1.0.0g and 1.0.0h [xx XXX xxxx]
*) Fix CVE-2011-4619: make sure we really are receiving a
client hello before rejecting multiple SGC restarts. Thanks to
Ivan Nestlerode <inestlerode@us.ibm.com> for discovering this bug.
[Steve Henson]
Changes between 1.0.0f and 1.0.0g [18 Jan 2012]
*) Fix for DTLS DoS issue introduced by fix for CVE-2011-4109.
...
...
ssl/s3_srvr.c
浏览文件 @
206310c3
...
...
@@ -873,14 +873,6 @@ int ssl3_check_client_hello(SSL *s)
int
ok
;
long
n
;
/* We only allow the client to restart the handshake once per
* negotiation. */
if
(
s
->
s3
->
flags
&
SSL3_FLAGS_SGC_RESTART_DONE
)
{
SSLerr
(
SSL_F_SSL3_CHECK_CLIENT_HELLO
,
SSL_R_MULTIPLE_SGC_RESTARTS
);
return
-
1
;
}
/* this function is called when we really expect a Certificate message,
* so permit appropriate message length */
n
=
s
->
method
->
ssl_get_message
(
s
,
...
...
@@ -893,6 +885,13 @@ int ssl3_check_client_hello(SSL *s)
s
->
s3
->
tmp
.
reuse_message
=
1
;
if
(
s
->
s3
->
tmp
.
message_type
==
SSL3_MT_CLIENT_HELLO
)
{
/* We only allow the client to restart the handshake once per
* negotiation. */
if
(
s
->
s3
->
flags
&
SSL3_FLAGS_SGC_RESTART_DONE
)
{
SSLerr
(
SSL_F_SSL3_CHECK_CLIENT_HELLO
,
SSL_R_MULTIPLE_SGC_RESTARTS
);
return
-
1
;
}
/* Throw away what we have done so far in the current handshake,
* which will now be aborted. (A full SSL_clear would be too much.) */
#ifndef OPENSSL_NO_DH
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录