Closed Bug 1398643 Opened 3 years ago Closed 3 years ago

Strictly prohibit renegotiation to change version

Categories

(NSS :: Libraries, enhancement, P2)

enhancement

Tracking

(Not tracked)

RESOLVED FIXED
Future

People

(Reporter: mt, Assigned: mt)

References

Details

Attachments

(1 file)

We currently don't allow renegotiation to change versions.  But the protection isn't complete, and there are still residues of the code that allowed it.  For instance, we check the pwSpec version rather than ss->version in a few places.

I've some code that clamps down much harder on this.  There are a few more checks and tests.  I've also removed the code that looks at the pending cipher spec.  That will help with another planned change.
Assignee: nobody → martin.thomson
See Also: → 1294697
Attachment #8906424 - Flags: review+
Priority: -- → P2
https://hg.mozilla.org/projects/nss/rev/7b73101f31b7d8f89061df28034f5942464bebae
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → Future
You need to log in before you can comment on or make changes to this bug.