Don't try and verify signatures if key is NULL (CVE-2013-0166)
authorDr. Stephen Henson <steve@openssl.org>
Thu, 24 Jan 2013 13:30:42 +0000 (13:30 +0000)
committerDr. Stephen Henson <steve@openssl.org>
Tue, 1 Apr 2014 15:39:35 +0000 (16:39 +0100)
commite9b4b8afbd129adc18d3fe71ca2ab34fe61d8640
tree6231ce8737298161827ae78914b0ee5278e7a12f
parentbc5ec653ba65fedb1619c8182088497de8a97a70
Don't try and verify signatures if key is NULL (CVE-2013-0166)
Add additional check to catch this in ASN1_item_verify too.
(cherry picked from commit 66e8211c0b1347970096e04b18aa52567c325200)
CHANGES
crypto/asn1/a_verify.c
crypto/ocsp/ocsp_vfy.c