ECDH downgrade bug fix.
authorDr. Stephen Henson <steve@openssl.org>
Fri, 24 Oct 2014 11:30:33 +0000 (12:30 +0100)
committerDr. Stephen Henson <steve@openssl.org>
Mon, 5 Jan 2015 23:34:57 +0000 (23:34 +0000)
commit4aaf1e493cb86efa64f6a486a27d38da6bce23af
tree201d689030a5f9faa5c2acaba8f60e89cd35bdfa
parentd96c24926d74aacbabe70f9ef49a0d260d9e2fad
ECDH downgrade bug fix.

Fix bug where an OpenSSL client would accept a handshake using an
ephemeral ECDH ciphersuites with the server key exchange message omitted.

Thanks to Karthikeyan Bhargavan for reporting this issue.

CVE-2014-3572
Reviewed-by: Matt Caswell <matt@openssl.org>
(cherry picked from commit b15f8769644b00ef7283521593360b7b2135cb63)
CHANGES
ssl/s3_clnt.c