summaryrefslogtreecommitdiffstats
path: root/NEWS
diff options
context:
space:
mode:
authorDr. Stephen Henson <steve@openssl.org>2015-10-02 12:35:19 +0100
committerMatt Caswell <matt@openssl.org>2015-12-03 14:32:05 +0000
commitc394a488942387246653833359a5c94b5832674e (patch)
tree5db97698a22d6e6c4753236e1311d067c18a93a9 /NEWS
parentd73cc256c8e256c32ed959456101b73ba9842f72 (diff)
Add PSS parameter check.
Avoid seg fault by checking mgf1 parameter is not NULL. This can be triggered during certificate verification so could be a DoS attack against a client or a server enabling client authentication. Thanks to Loïc Jonas Etienne (Qnective AG) for discovering this bug. CVE-2015-3194 Reviewed-by: Richard Levitte <levitte@openssl.org>
Diffstat (limited to 'NEWS')
0 files changed, 0 insertions, 0 deletions