Dr. Stephen Henson e42a2abadc ECDH downgrade bug fix.
Fix bug where an OpenSSL client would accept a handshake using an
ephemeral ECDH ciphersuites with the server key exchange message omitted.

Thanks to Karthikeyan Bhargavan for reporting this issue.

CVE-2014-3572
Reviewed-by: Matt Caswell <matt@openssl.org>

(cherry picked from commit b15f8769644b00ef7283521593360b7b2135cb63)

Conflicts:
	CHANGES
	ssl/s3_clnt.c
2015-01-05 23:59:04 +00:00
..
2011-05-25 15:15:43 +00:00
2014-08-06 22:02:00 +01:00
2014-10-15 04:18:29 +02:00
2014-10-15 04:18:29 +02:00
2014-09-24 16:01:46 +02:00
2013-02-05 16:50:32 +00:00
2014-10-15 04:18:29 +02:00
2013-02-05 16:50:32 +00:00
2011-02-03 12:04:48 +00:00
2013-02-05 16:50:32 +00:00
2015-01-05 23:59:04 +00:00
2014-10-15 04:18:29 +02:00
2014-10-15 04:18:29 +02:00
2014-09-24 16:01:46 +02:00
2014-10-15 08:46:57 -04:00
2002-07-10 07:01:54 +00:00
2014-10-21 21:32:50 +02:00
2001-11-10 01:16:28 +00:00
2014-10-15 04:18:29 +02:00
2010-03-24 23:16:35 +00:00
2014-10-15 04:18:29 +02:00
2009-09-12 23:09:59 +00:00
2010-02-01 16:48:40 +00:00
2010-02-22 07:05:24 +00:00
2013-02-11 18:27:33 +00:00
2014-10-15 04:18:29 +02:00
2014-10-15 08:46:57 -04:00
2009-12-27 23:03:40 +00:00