commit | 56475207be81018cdd7e2b410d5a5fc4ec0c03b8 | [log] [tgz] |
---|---|---|
author | Adam Langley <agl@chromium.org> | Fri Jun 20 12:00:00 2014 -0700 |
committer | Adam Langley <agl@chromium.org> | Fri Jun 20 13:17:39 2014 -0700 |
tree | c92dd446b7a7ad055115dd64e59902106780327a | |
parent | 45ba42a94c8109fa2be91c565a071a93588cde8c [diff] |
Add heartbeat extension bounds check. A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server. Thanks for Neel Mehta of Google Security for discovering this bug and to Adam Langley <agl@chromium.org> and Bodo Moeller <bmoeller@acm.org> for preparing the fix (CVE-2014-0160) (Imported from upstream's 7e840163c06c7692b796a93e3fa85a93136adbb2)