[openssl.org #3377] 0.9.8za/1.0.0m incomplete backport from 1.0.1h in ssl/s3_pkt.c

2014-06-12 Thread Matt Caswell via RT
Fixed. I have made the following commit to master and 1.0.2: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=d84ba7ea23b386f3fe56c4fe7a7aa8ece2e0c356 And this one to 1.0.0 and 0.9.8: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=d663f506dc43752b64db58e9169e2e200b3b4be6 Many

[openssl.org #3377] 0.9.8za/1.0.0m incomplete backport from 1.0.1h in ssl/s3_pkt.c

2014-06-05 Thread Rainer Jung via RT
Commit 989d87cb1a174a951efd829ff6b2f68a322f9df8 for 1.0.1 was shortly after improved by commit dac3654e2d89d43807e7b8e4b9da86ae1d33fe2b. It changed s-s3-wnum INT_MAX to s-s3-wnum = INT_MAX (lower or equals instead of lower than). The backports to 1.0.0 and 0.9.8 only contained the first commit,