8d038a08fb
'len' argument to BUF_MEM_grow and BUF_MEM_grow_clean is an int in OpenSSL 0.9.8, making it still vulnerable. Fix by rejecting negative len parameter. Thanks to the many people who reported this bug and to Tomas Hoger <thoger@redhat.com> for supplying the fix. |
||
---|---|---|
.. | ||
.cvsignore | ||
buf_err.c | ||
buf_str.c | ||
buffer.c | ||
buffer.h | ||
Makefile |