Closed Bug 1398643 Opened 3 years ago Closed 3 years ago
Strictly prohibit renegotiation to change version
3 years ago
44 bytes, text/x-phabricator-request
|Details | Review|
We currently don't allow renegotiation to change versions. But the protection isn't complete, and there are still residues of the code that allowed it. For instance, we check the pwSpec version rather than ss->version in a few places. I've some code that clamps down much harder on this. There are a few more checks and tests. I've also removed the code that looks at the pending cipher spec. That will help with another planned change.
Assignee: nobody → martin.thomson
See Also: → 1294697
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → Future
You need to log in before you can comment on or make changes to this bug.