mirror of
https://git.suyu.dev/suyu/mbedtls.git
synced 2025-12-21 21:36:21 +01:00
Forbid extended master secret with SSLv3
This commit is contained in:
parent
dd4592774b
commit
b575b54cb9
3 changed files with 31 additions and 3 deletions
|
|
@ -365,7 +365,8 @@ static void ssl_write_extended_ms_ext( ssl_context *ssl,
|
|||
{
|
||||
unsigned char *p = buf;
|
||||
|
||||
if( ssl->extended_ms == SSL_EXTENDED_MS_DISABLED )
|
||||
if( ssl->extended_ms == SSL_EXTENDED_MS_DISABLED ||
|
||||
ssl->max_minor_ver == SSL_MINOR_VERSION_0 )
|
||||
{
|
||||
*olen = 0;
|
||||
return;
|
||||
|
|
@ -816,6 +817,7 @@ static int ssl_parse_extended_ms_ext( ssl_context *ssl,
|
|||
size_t len )
|
||||
{
|
||||
if( ssl->extended_ms == SSL_EXTENDED_MS_DISABLED ||
|
||||
ssl->minor_ver == SSL_MINOR_VERSION_0 ||
|
||||
len != 0 )
|
||||
{
|
||||
return( POLARSSL_ERR_SSL_BAD_HS_SERVER_HELLO );
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue