Emilia Kasper 294d1e36c2 RT3066: rewrite RSA padding checks to be slightly more constant time.
Also tweak s3_cbc.c to use new constant-time methods.
Also fix memory leaks from internal errors in RSA_padding_check_PKCS1_OAEP_mgf1

This patch is based on the original RT submission by Adam Langley <agl@chromium.org>,
as well as code from BoringSSL and OpenSSL.

Reviewed-by: Kurt Roeckx <kurt@openssl.org>
2014-09-24 12:45:42 +02:00
..
2013-06-21 23:43:05 +01:00
2011-02-21 17:35:53 +00:00
2006-01-29 23:12:22 +00:00
2011-01-26 15:37:41 +00:00
2008-11-05 18:39:08 +00:00
2013-06-21 23:43:05 +01:00
2008-11-05 18:39:08 +00:00