• V S Murthy Sidagam's avatar
    Description: yaSSL was only handling the cases of zero or · 8c65e082
    V S Murthy Sidagam authored
    one leading zeros for the key agreement instead of
    potentially any number.
    There is about 1 in 50,000 connections to fail
    when using DHE cipher suites.  The second problem was the
    case where a server would send a public value shorter than
    the prime value, causing about 1 in 128 client connections
    to fail, and also caused the yaSSL client to read off the
    end of memory.
    All client side DHE cipher suite users should update.
    Note: The patch is received from YaSSL people
    8c65e082
yassl_int.cpp 61.2 KB