Dr. Stephen Henson c394a48894 Add PSS parameter check.
Avoid seg fault by checking mgf1 parameter is not NULL. This can be
triggered during certificate verification so could be a DoS attack
against a client or a server enabling client authentication.

Thanks to Loïc Jonas Etienne (Qnective AG) for discovering this bug.

CVE-2015-3194

Reviewed-by: Richard Levitte <levitte@openssl.org>
2015-12-03 14:32:05 +00:00
..
2015-12-03 14:32:05 +00:00
2015-04-30 23:21:53 +01:00
2015-09-01 20:02:54 +02:00
2015-01-22 09:31:38 +00:00