(EC)DH memory handling fixes.
Submitted by: Adam Langley
This commit is contained in:
parent
7f1022a8b1
commit
61ac68f9f6
8
CHANGES
8
CHANGES
@ -164,6 +164,10 @@
|
|||||||
|
|
||||||
Changes between 1.0.0d and 1.0.0e [xx XXX xxxx]
|
Changes between 1.0.0d and 1.0.0e [xx XXX xxxx]
|
||||||
|
|
||||||
|
*) Fix SSL memory handling for (EC)DH ciphersuites, in particular
|
||||||
|
for multi-threaded use of ECDH.
|
||||||
|
[Adam Langley (Google)]
|
||||||
|
|
||||||
*) Fix x509_name_ex_d2i memory leak on bad inputs.
|
*) Fix x509_name_ex_d2i memory leak on bad inputs.
|
||||||
[Bodo Moeller]
|
[Bodo Moeller]
|
||||||
|
|
||||||
@ -1061,6 +1065,10 @@
|
|||||||
|
|
||||||
Changes between 0.9.8r and 0.9.8s [xx XXX xxxx]
|
Changes between 0.9.8r and 0.9.8s [xx XXX xxxx]
|
||||||
|
|
||||||
|
*) Fix SSL memory handling for (EC)DH ciphersuites, in particular
|
||||||
|
for multi-threaded use of ECDH.
|
||||||
|
[Adam Langley (Google)]
|
||||||
|
|
||||||
*) Fix x509_name_ex_d2i memory leak on bad inputs.
|
*) Fix x509_name_ex_d2i memory leak on bad inputs.
|
||||||
[Bodo Moeller]
|
[Bodo Moeller]
|
||||||
|
|
||||||
|
@ -1031,12 +1031,11 @@ int dtls1_send_server_key_exchange(SSL *s)
|
|||||||
SSLerr(SSL_F_DTLS1_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
SSLerr(SSL_F_DTLS1_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (!EC_KEY_up_ref(ecdhp))
|
if ((ecdh = EC_KEY_dup(ecdhp)) == NULL)
|
||||||
{
|
{
|
||||||
SSLerr(SSL_F_DTLS1_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
SSLerr(SSL_F_DTLS1_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
ecdh = ecdhp;
|
|
||||||
|
|
||||||
s->s3->tmp.ecdh=ecdh;
|
s->s3->tmp.ecdh=ecdh;
|
||||||
if ((EC_KEY_get0_public_key(ecdh) == NULL) ||
|
if ((EC_KEY_get0_public_key(ecdh) == NULL) ||
|
||||||
|
@ -3021,11 +3021,17 @@ void ssl3_clear(SSL *s)
|
|||||||
}
|
}
|
||||||
#ifndef OPENSSL_NO_DH
|
#ifndef OPENSSL_NO_DH
|
||||||
if (s->s3->tmp.dh != NULL)
|
if (s->s3->tmp.dh != NULL)
|
||||||
|
{
|
||||||
DH_free(s->s3->tmp.dh);
|
DH_free(s->s3->tmp.dh);
|
||||||
|
s->s3->tmp.dh = NULL;
|
||||||
|
}
|
||||||
#endif
|
#endif
|
||||||
#ifndef OPENSSL_NO_ECDH
|
#ifndef OPENSSL_NO_ECDH
|
||||||
if (s->s3->tmp.ecdh != NULL)
|
if (s->s3->tmp.ecdh != NULL)
|
||||||
|
{
|
||||||
EC_KEY_free(s->s3->tmp.ecdh);
|
EC_KEY_free(s->s3->tmp.ecdh);
|
||||||
|
s->s3->tmp.ecdh = NULL;
|
||||||
|
}
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
rp = s->s3->rbuf.buf;
|
rp = s->s3->rbuf.buf;
|
||||||
|
@ -847,15 +847,20 @@ int ssl3_check_client_hello(SSL *s)
|
|||||||
if (s->s3->tmp.message_type == SSL3_MT_CLIENT_HELLO)
|
if (s->s3->tmp.message_type == SSL3_MT_CLIENT_HELLO)
|
||||||
{
|
{
|
||||||
/* Throw away what we have done so far in the current handshake,
|
/* Throw away what we have done so far in the current handshake,
|
||||||
* which will now be aborted. (A full SSL_clear would be too much.)
|
* which will now be aborted. (A full SSL_clear would be too much.) */
|
||||||
* I hope that tmp.dh is the only thing that may need to be cleared
|
|
||||||
* when a handshake is not completed ... */
|
|
||||||
#ifndef OPENSSL_NO_DH
|
#ifndef OPENSSL_NO_DH
|
||||||
if (s->s3->tmp.dh != NULL)
|
if (s->s3->tmp.dh != NULL)
|
||||||
{
|
{
|
||||||
DH_free(s->s3->tmp.dh);
|
DH_free(s->s3->tmp.dh);
|
||||||
s->s3->tmp.dh = NULL;
|
s->s3->tmp.dh = NULL;
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
#ifndef OPENSSL_NO_ECDH
|
||||||
|
if (s->s3->tmp.ecdh != NULL)
|
||||||
|
{
|
||||||
|
EC_KEY_free(s->s3->tmp.ecdh);
|
||||||
|
s->s3->tmp.ecdh = NULL;
|
||||||
|
}
|
||||||
#endif
|
#endif
|
||||||
return 2;
|
return 2;
|
||||||
}
|
}
|
||||||
@ -1578,7 +1583,6 @@ int ssl3_send_server_key_exchange(SSL *s)
|
|||||||
|
|
||||||
if (s->s3->tmp.dh != NULL)
|
if (s->s3->tmp.dh != NULL)
|
||||||
{
|
{
|
||||||
DH_free(dh);
|
|
||||||
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE, ERR_R_INTERNAL_ERROR);
|
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE, ERR_R_INTERNAL_ERROR);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
@ -1639,7 +1643,6 @@ int ssl3_send_server_key_exchange(SSL *s)
|
|||||||
|
|
||||||
if (s->s3->tmp.ecdh != NULL)
|
if (s->s3->tmp.ecdh != NULL)
|
||||||
{
|
{
|
||||||
EC_KEY_free(s->s3->tmp.ecdh);
|
|
||||||
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE, ERR_R_INTERNAL_ERROR);
|
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE, ERR_R_INTERNAL_ERROR);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
@ -1650,12 +1653,11 @@ int ssl3_send_server_key_exchange(SSL *s)
|
|||||||
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (!EC_KEY_up_ref(ecdhp))
|
if ((ecdh = EC_KEY_dup(ecdhp)) == NULL)
|
||||||
{
|
{
|
||||||
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
SSLerr(SSL_F_SSL3_SEND_SERVER_KEY_EXCHANGE,ERR_R_ECDH_LIB);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
ecdh = ecdhp;
|
|
||||||
|
|
||||||
s->s3->tmp.ecdh=ecdh;
|
s->s3->tmp.ecdh=ecdh;
|
||||||
if ((EC_KEY_get0_public_key(ecdh) == NULL) ||
|
if ((EC_KEY_get0_public_key(ecdh) == NULL) ||
|
||||||
@ -2567,6 +2569,12 @@ int ssl3_get_client_key_exchange(SSL *s)
|
|||||||
/* Get encoded point length */
|
/* Get encoded point length */
|
||||||
i = *p;
|
i = *p;
|
||||||
p += 1;
|
p += 1;
|
||||||
|
if (n != 1 + i)
|
||||||
|
{
|
||||||
|
SSLerr(SSL_F_SSL3_GET_CLIENT_KEY_EXCHANGE,
|
||||||
|
ERR_R_EC_LIB);
|
||||||
|
goto err;
|
||||||
|
}
|
||||||
if (EC_POINT_oct2point(group,
|
if (EC_POINT_oct2point(group,
|
||||||
clnt_ecpoint, p, i, bn_ctx) == 0)
|
clnt_ecpoint, p, i, bn_ctx) == 0)
|
||||||
{
|
{
|
||||||
|
Loading…
x
Reference in New Issue
Block a user