Skip to content
  • Andy Polyakov's avatar
    crypto/evp: harden AEAD ciphers. · 2198b3a5
    Andy Polyakov authored
    
    
    Originally a crash in 32-bit build was reported CHACHA20-POLY1305
    cipher. The crash is triggered by truncated packet and is result
    of excessive hashing to the edge of accessible memory. Since hash
    operation is read-only it is not considered to be exploitable
    beyond a DoS condition. Other ciphers were hardened.
    
    Thanks to Robert Święcki for report.
    
    CVE-2017-3731
    
    Reviewed-by: default avatarRich Salz <rsalz@openssl.org>
    2198b3a5