diff options
author | Arun Kuruvila <arun.kuruvila@oracle.com> | 2017-08-24 14:19:38 +0530 |
---|---|---|
committer | Arun Kuruvila <arun.kuruvila@oracle.com> | 2017-08-24 14:19:38 +0530 |
commit | f2f6025a445d9a799ccce27bc9124c3a63c28764 (patch) | |
tree | fcba66b433dcb5e4294fdadc8479129229112c7a /extra/yassl/README | |
parent | be901b60ae59c93848c829d1b0b2cb523ab8692e (diff) | |
download | mariadb-git-f2f6025a445d9a799ccce27bc9124c3a63c28764.tar.gz |
Bug#26482173: TLS CIPHER NEGOTIATION INCORRECTLY MATCHES ON
LAST BYTE ONLY (YASSL)
Description:- TLS cipher negociation happens incorrectly
leading to the use of a different
Analysis:- YaSSL based MySQL server will compare only the
last byte of each cipher sent in the Client Hello message.
This can cause TLS connections to fail, due to the server
picking a cipher which the client doesn't actually support.
Fix:- A fix for detecting cipher suites with non leading
zeros is included as YaSSL only supports cipher suites with
leading zeros.
Diffstat (limited to 'extra/yassl/README')
-rw-r--r-- | extra/yassl/README | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/extra/yassl/README b/extra/yassl/README index a3d4f60f561..de1bf5132aa 100644 --- a/extra/yassl/README +++ b/extra/yassl/README @@ -12,6 +12,14 @@ before calling SSL_new(); *** end Note *** +yaSSL Release notes, version 2.4.4 (8/8/2017) + This release of yaSSL fixes an interop issue. A fix for detecting cipher + suites with non leading zeros is included as yaSSL only supports cipher + suites with leading zeros. Thanks for the report from Security Innovation + and Oracle. + + Users interoping with other SSL stacks should update. + yaSSL Release notes, version 2.4.2 (9/22/2016) This release of yaSSL fixes a medium security vulnerability. A fix for potential AES side channel leaks is included that a local user monitoring |