Don't try and verify signatures if key is NULL (CVE-2013-0166)
authorDr. Stephen Henson <steve@openssl.org>
Thu, 24 Jan 2013 13:30:42 +0000 (13:30 +0000)
committerDr. Stephen Henson <steve@openssl.org>
Tue, 5 Feb 2013 16:50:31 +0000 (16:50 +0000)
commit66e8211c0b1347970096e04b18aa52567c325200
treeb466e3e26ccd1601ab5f45f79ba8d7256086eba8
parentdd2dee60f343a28cd93e065c7dae7619885515ff
Don't try and verify signatures if key is NULL (CVE-2013-0166)
Add additional check to catch this in ASN1_item_verify too.
CHANGES
crypto/asn1/a_verify.c
crypto/ocsp/ocsp_vfy.c