Heartbeat Response transmission during handshake - plaintext bleeding of HB response [CVE-2014-0160]

2014-04-12 Thread MiW on Mailing Lists
Hi List, I think Doug Smith was correct in his email "Heartbeat response during handshake?" RFC 6520 does state "that The receiving peer SHOULD discard the message silently, if it arrives during the handshake.". I was testing adding the following lines to d1_both.c and t1_lib.c in the tls1_proce

Heartbeat Response transmission during handshake?

2014-04-08 Thread Doug Smith
Is openssl sending heartbeat response packets during the handshake, and if so, should it be sending them during the handshake? The heartbleed web site indicates that openssl is responding to heartbeat requests during the handshake. http://heartbleed.com/ "... heartbeat request can be sent and is