mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-02-19 09:40:29 +00:00
11 lines
643 B
Plaintext
11 lines
643 B
Plaintext
Security
|
|
* When negotiating TLS version on server side, do not fallback to the
|
|
TLS 1.2 implementation of the protocol if it is not enabled.
|
|
- If the TLS 1.2 implementation was disabled at build time, a TLS 1.2
|
|
client was able to put the TLS 1.3-only server in an infinite loop
|
|
processing a TLS 1.2 ClientHello, resulting in a Denial of Service.
|
|
Reported by Matthias Mucha and Thomas Blattmann, SICK AG.
|
|
- If the TLS 1.2 implementation was disabled at runtime, a TLS 1.2 client
|
|
was able to successfully established a connection with the TLS 1.3-only
|
|
server. Reported by alluettiv on GitHub.
|