Dr. Stephen Henson 09f06923e6 Reject invalid PSS parameters.
Fix a bug where invalid PSS parameters are not rejected resulting in a
NULL pointer exception. This can be triggered during certificate
verification so could be a DoS attack against a client or a server
enabling client authentication.

Thanks to Brian Carpenter for reporting this issues.

CVE-2015-0208

Reviewed-by: Tim Hudson <tjh@openssl.org>
2015-03-19 13:01:13 +00:00
..
2015-03-19 13:01:13 +00:00
2015-01-27 12:34:45 -05:00
2015-01-27 12:34:45 -05:00
2015-03-12 09:26:14 +00:00
2015-01-27 10:06:22 -05:00