CVSROOT:        /cvs
Module name:    src
Changes by:     st...@cvs.openbsd.org   2014/06/05 14:12:12

Modified files:
        lib/libssl/src/ssl: Tag: OPENBSD_5_5 d1_both.c 

Log message:
MFC DTLS "Hello Request" fix (CVE-2014-0221)

"Do not recurse when a 'Hello Request' message is received while getting
DTLS fragments. A stream of 'Hello Request' messages will result in
infinite recursion, eventually crashing the DTLS client or server.
Fixes CVE-2014-0221, from OpenSSL.  Reported to OpenSSL by Imre Rad."
>From d1_both.c r1.20


Reply via email to