mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-10-04 07:57:23 +00:00
Restrict mapping of UNEXPECTED_RECORD to UNEXPECTED_MESSAGE
Signed-off-by: Ronald Cron <[email protected]>
This commit is contained in:
@@ -923,6 +923,7 @@ static int ssl_parse_client_hello(mbedtls_ssl_context *ssl)
|
|||||||
if ((ret = mbedtls_ssl_read_record(ssl, 0)) != 0) {
|
if ((ret = mbedtls_ssl_read_record(ssl, 0)) != 0) {
|
||||||
MBEDTLS_SSL_DEBUG_RET(1, "mbedtls_ssl_read_record ", ret);
|
MBEDTLS_SSL_DEBUG_RET(1, "mbedtls_ssl_read_record ", ret);
|
||||||
|
|
||||||
|
#if defined(MBEDTLS_SSL_PROTO_DTLS)
|
||||||
/*
|
/*
|
||||||
* In the case of an alert message corresponding to the termination of
|
* In the case of an alert message corresponding to the termination of
|
||||||
* a previous connection, `ssl_parse_record_header()` and then
|
* a previous connection, `ssl_parse_record_header()` and then
|
||||||
@@ -943,9 +944,16 @@ static int ssl_parse_client_hello(mbedtls_ssl_context *ssl)
|
|||||||
* used to detect a specific error condition, so this mapping
|
* used to detect a specific error condition, so this mapping
|
||||||
* should not remove any meaningful distinction.
|
* should not remove any meaningful distinction.
|
||||||
*/
|
*/
|
||||||
if (ret == MBEDTLS_ERR_SSL_UNEXPECTED_RECORD) {
|
if ((ssl->conf->transport == MBEDTLS_SSL_TRANSPORT_DATAGRAM)
|
||||||
ret = MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE;
|
#if defined(MBEDTLS_SSL_RENEGOTIATION)
|
||||||
|
&& (ssl->renego_status == MBEDTLS_SSL_INITIAL_HANDSHAKE)
|
||||||
|
#endif
|
||||||
|
) {
|
||||||
|
if (ret == MBEDTLS_ERR_SSL_UNEXPECTED_RECORD) {
|
||||||
|
ret = MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
#endif /* MBEDTLS_SSL_PROTO_DTLS */
|
||||||
|
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user