diff options
author | jsing <> | 2016-11-03 08:15:22 +0000 |
---|---|---|
committer | jsing <> | 2016-11-03 08:15:22 +0000 |
commit | 463a204c858ff0b4b4b13aed4ed5f6d5670a5c8b (patch) | |
tree | 2c9e9177516e955488acfb0b61a4dbeb7b177ab5 /src/lib/libcrypto/man/OPENSSL_load_builtin_modules.3 | |
parent | 16110475192553519ce33e3c5ab81eed49bdba30 (diff) | |
download | openbsd-463a204c858ff0b4b4b13aed4ed5f6d5670a5c8b.tar.gz openbsd-463a204c858ff0b4b4b13aed4ed5f6d5670a5c8b.tar.bz2 openbsd-463a204c858ff0b4b4b13aed4ed5f6d5670a5c8b.zip |
Clean up the TLS handshake digest handling - this refactors some of the
code for improved readability, however it also address two issues.
The first of these is a hard-to-hit double free that will occur if
EVP_DigestInit_ex() fails. To avoid this and to be more robust, ensure
that tls1_digest_cached_records() either completes successfully and sets
up all of the necessary digests, or it cleans up and frees everything
that was allocated.
The second issue is that EVP_DigestUpdate() can fail - detect and handle
this in tls1_finish_mac() and change the return type to an int so that a
failure can be propagated to the caller (the callers still need to be
fixed to handle this, in a later diff).
The double-free was reported by Matthew Dillon.
ok beck@ doug@ miod@
Diffstat (limited to 'src/lib/libcrypto/man/OPENSSL_load_builtin_modules.3')
0 files changed, 0 insertions, 0 deletions