Dr. Stephen Henson ef28c6d676 ECDH downgrade bug fix.
Fix bug where an OpenSSL client would accept a handshake using an
ephemeral ECDH ciphersuites with the server key exchange message omitted.

Thanks to Karthikeyan Bhargavan for reporting this issue.

CVE-2014-3572
Reviewed-by: Matt Caswell <matt@openssl.org>

(cherry picked from commit b15f8769644b00ef7283521593360b7b2135cb63)
2015-01-05 23:48:55 +00:00
..
2012-04-16 17:43:15 +00:00
2014-10-15 08:51:49 -04:00
2009-04-21 22:20:12 +00:00
2014-02-26 15:33:09 +00:00
2014-09-24 15:52:41 +02:00
2013-01-28 17:30:38 +00:00
2014-11-27 21:53:44 +00:00
2014-10-15 04:05:42 +02:00
2015-01-05 23:48:55 +00:00
2014-10-15 08:51:50 -04:00
2002-07-10 07:01:54 +00:00
2014-10-15 04:05:42 +02:00
2012-06-08 09:18:47 +00:00
2014-10-28 17:41:49 +01:00
2011-05-11 13:37:52 +00:00
2011-05-11 13:37:52 +00:00
2015-01-02 22:30:20 +00:00
2011-05-11 13:37:52 +00:00
2009-12-27 22:59:09 +00:00
2011-05-11 13:37:52 +00:00
2014-10-15 04:05:42 +02:00
2014-08-06 20:27:51 +01:00