ECDH downgrade bug fix.
authorDr. Stephen Henson <steve@openssl.org>
Fri, 24 Oct 2014 11:30:33 +0000 (12:30 +0100)
committerDr. Stephen Henson <steve@openssl.org>
Mon, 5 Jan 2015 22:59:32 +0000 (22:59 +0000)
commitb15f8769644b00ef7283521593360b7b2135cb63
treeb4d18627db345215516e44ce4463cfc011b566f8
parentb5526482ef81ee7906b967e326d23a45fbcf3abc
ECDH downgrade bug fix.

Fix bug where an OpenSSL client would accept a handshake using an
ephemeral ECDH ciphersuites with the server key exchange message omitted.

Thanks to Karthikeyan Bhargavan for reporting this issue.

CVE-2014-3572
Reviewed-by: Matt Caswell <matt@openssl.org>
CHANGES
ssl/s3_clnt.c