Dr. Stephen Henson 966fe81f9b Fix SRP buffer overrun vulnerability.
Invalid parameters passed to the SRP code can be overrun an internal
buffer. Add sanity check that g, A, B < N to SRP code.

Thanks to Sean Devlin and Watson Ladd of Cryptography Services, NCC
Group for reporting this issue.
Reviewed-by: Kurt Roeckx <kurt@openssl.org>
2014-08-06 20:27:51 +01:00
..
2014-08-06 20:27:51 +01:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-06-30 14:00:00 +01:00
2014-01-06 13:33:27 +00:00
2014-06-28 00:06:40 +01:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-08-06 20:27:51 +01:00
2014-07-06 00:36:11 +01:00
2012-06-08 09:18:47 +00:00
2014-05-29 14:12:14 +01:00
2014-01-06 13:33:27 +00:00
2014-08-01 18:42:40 +01:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-07-05 22:38:44 +01:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-08-06 20:27:51 +01:00
2014-01-06 13:33:27 +00:00
2009-02-19 09:42:51 +00:00
2014-04-22 17:02:37 +01:00
2014-01-06 13:33:27 +00:00
2014-01-06 13:33:27 +00:00
2014-04-15 18:53:04 +01:00
2011-08-12 12:31:08 +00:00
2012-06-08 09:18:47 +00:00
2012-07-05 12:58:27 +00:00
2013-01-28 17:30:38 +00:00
2000-02-01 02:21:16 +00:00
2011-10-21 13:04:27 +00:00
2011-06-21 16:58:10 +00:00
2006-10-23 07:41:05 +00:00
2014-01-06 13:33:27 +00:00
2007-06-23 18:47:51 +00:00
2009-04-16 17:22:51 +00:00
2012-06-08 09:18:47 +00:00
2009-06-01 12:14:15 +00:00
2014-06-05 10:45:50 +01:00
2014-01-11 22:42:37 +00:00
2003-11-28 13:10:58 +00:00