From 1acca28263f6f16f60c25b97eb82dca61ad5df88 Mon Sep 17 00:00:00 2001 From: Bodo Moeller Date: Tue, 21 Oct 2014 22:33:03 +0200 Subject: When processing ClientHello.cipher_suites, don't ignore cipher suites listed after TLS_FALLBACK_SCSV. RT: 3575 Reviewed-by: Emilia Kasper --- ssl/ssl_lib.c | 1 + 1 file changed, 1 insertion(+) (limited to 'ssl') diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c index 5db0b5276e..542ab5a558 100644 --- a/ssl/ssl_lib.c +++ b/ssl/ssl_lib.c @@ -1401,6 +1401,7 @@ STACK_OF(SSL_CIPHER) *ssl_bytes_to_cipher_list(SSL *s,unsigned char *p,int num, ssl3_send_alert(s,SSL3_AL_FATAL,SSL_AD_INAPPROPRIATE_FALLBACK); goto err; } + p += n; continue; } -- cgit v1.2.3