Merge remote-tracking branch 'public/pr/2113' into mbedtls-2.1-proposed

This commit is contained in:
Simon Butcher 2018-10-28 16:32:05 +00:00
commit 351c4f15f4
2 changed files with 9 additions and 6 deletions

View File

@ -9,6 +9,9 @@ Bugfix
invalidated keys of a lifetime of less than a 1s. Fixes #1968.
* Fix potential build failures related to the 'apidoc' target, introduced
in the previous patch release. Found by Robert Scheck. #390 #391
* Fix a bug in the record decryption routine ssl_decrypt_buf()
which lead to accepting properly authenticated but improperly
padded records in case of CBC ciphersuites using Encrypt-then-MAC.
Changes
* "make apidoc" now generates the documentation for the current

View File

@ -2110,13 +2110,13 @@ static int ssl_decrypt_buf( mbedtls_ssl_context *ssl )
correct = 0;
}
auth_done++;
/*
* Finally check the correct flag
*/
if( correct == 0 )
return( MBEDTLS_ERR_SSL_INVALID_MAC );
}
/*
* Finally check the correct flag
*/
if( correct == 0 )
return( MBEDTLS_ERR_SSL_INVALID_MAC );
#endif /* SSL_SOME_MODES_USE_MAC */
/* Make extra sure authentication was performed, exactly once */