Closed
Bug 1398643
Opened 7 years ago
Closed 7 years ago
Strictly prohibit renegotiation to change version
Categories
(NSS :: Libraries, enhancement, P2)
NSS
Libraries
Tracking
(Not tracked)
RESOLVED
FIXED
Future
People
(Reporter: mt, Assigned: mt)
References
Details
Attachments
(1 file)
We currently don't allow renegotiation to change versions. But the protection isn't complete, and there are still residues of the code that allowed it. For instance, we check the pwSpec version rather than ss->version in a few places. I've some code that clamps down much harder on this. There are a few more checks and tests. I've also removed the code that looks at the pending cipher spec. That will help with another planned change.
Updated•7 years ago
|
Attachment #8906424 -
Flags: review+
Updated•7 years ago
|
Priority: -- → P2
Assignee | ||
Comment 1•7 years ago
|
||
https://hg.mozilla.org/projects/nss/rev/7b73101f31b7d8f89061df28034f5942464bebae
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
Target Milestone: --- → Future
You need to log in
before you can comment on or make changes to this bug.
Description
•