ACK ("stared at code").  

Have no ASAN setup here so replicating the original problem involved
a bit of extra msg()'ing and then scratching my head, but I can confirm
that the original math ended up with an integer underflow / unsigned,
and the comarison not firing...

Your patch has been applied to the master, release/2.4 and release/2.3 branch.

commit e6bf7e033d063535a4414a4cf49c8f367ecdbb4f (master)
commit b52c1ff43b23c3cf438fb99b807a7309d3229a56 (release/2.4)
commit 236807276368514f8ab80155f440a1d377ab412b (release/2.3)
Author: Steffan Karger
Date:   Mon May 22 15:54:13 2017 +0200

     openssl: fix overflow check for long --tls-cipher option

     Signed-off-by: Steffan Karger <steffan.kar...@fox-it.com>
     Acked-by: Gert Doering <g...@greenie.muc.de>
     Message-Id: <1495461253-20111-1-git-send-email-steffan.kar...@fox-it.com>
     URL: 
https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg14716.html
     Signed-off-by: Gert Doering <g...@greenie.muc.de>


--
kind regards,

Gert Doering


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to