Add fix for CVE-2013-4353

This commit is contained in:
Dr. Stephen Henson 2014-01-07 15:37:35 +00:00
parent a05a2c67ef
commit 2f972419a3

View File

@ -203,7 +203,11 @@ static void ssl3_take_mac(SSL *s)
{
const char *sender;
int slen;
/* If no new cipher setup return immediately: other functions will
* set the appropriate error.
*/
if (s->s3->tmp.new_cipher == NULL)
return;
if (s->state & SSL_ST_CONNECT)
{
sender=s->method->ssl3_enc->server_finished_label;