]> git.ipfire.org Git - thirdparty/openssl.git/commit
rsa/rsa_ssl.c: make RSA_padding_check_SSLv23 constant-time.
authorAndy Polyakov <appro@openssl.org>
Fri, 14 Sep 2018 15:24:13 +0000 (17:24 +0200)
committerMatt Caswell <matt@openssl.org>
Thu, 6 Dec 2018 11:18:35 +0000 (11:18 +0000)
commit110ef88b99f1acc6b976f2e49153734924181db2
treeec5f36ddd1d1ffc342ab2659686d12b90c5b3051
parentb29b91bc7ea8dfe47d873d7953175c57556a4488
rsa/rsa_ssl.c: make RSA_padding_check_SSLv23 constant-time.

Copy of RSA_padding_check_PKCS1_type_2 with a twist that rejects padding
if nul delimiter is preceded by 8 consecutive 0x03 bytes.

Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(cherry picked from commit 603221407ddc6404f8c417c6beadebf84449074c)

Resolved conflicts:
crypto/rsa/rsa_ssl.c

(Merged from https://github.com/openssl/openssl/pull/7737)
crypto/rsa/rsa_ssl.c