Fix DTLS anonymous EC(DH) denial of service
authorEmilia Käsper <emilia@openssl.org>
Thu, 24 Jul 2014 20:15:29 +0000 (22:15 +0200)
committerMatt Caswell <matt@openssl.org>
Wed, 6 Aug 2014 19:36:40 +0000 (20:36 +0100)
CVE-2014-3510

Reviewed-by: Dr. Stephen Henson <steve@openssl.org>
ssl/s3_clnt.c

index 9a94de0..0a006a7 100644 (file)
@@ -2385,6 +2385,13 @@ int ssl3_send_client_key_exchange(SSL *s)
                        RSA *rsa;
                        unsigned char tmp_buf[SSL_MAX_MASTER_KEY_LENGTH];
 
+                       if (s->session->sess_cert == NULL)
+                               {
+                               /* We should always have a server certificate with SSL_kRSA. */
+                               SSLerr(SSL_F_SSL3_SEND_CLIENT_KEY_EXCHANGE,ERR_R_INTERNAL_ERROR);
+                               goto err;
+                               }
+
                        if (s->session->sess_cert->peer_rsa_tmp != NULL)
                                rsa=s->session->sess_cert->peer_rsa_tmp;
                        else