From c698aceb43400cc7e94ece59cf630b1ff99e1e34 Mon Sep 17 00:00:00 2001 From: maoyufeng Date: Wed, 29 Dec 2021 19:29:03 +0800 Subject: [PATCH] fixed 69750b8 from https://gitee.com/rain_myf/third_party_mbedtls/pulls/28 Fix CVE-2021-44732 CVE-2021-45450 Signed-off-by: maoyufeng --- library/ssl_tls.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/library/ssl_tls.c b/library/ssl_tls.c index c749a8611..48ed2cb28 100755 --- a/library/ssl_tls.c +++ b/library/ssl_tls.c @@ -301,6 +301,10 @@ static int ssl_session_copy( mbedtls_ssl_session *dst, const mbedtls_ssl_session mbedtls_ssl_session_free( dst ); memcpy( dst, src, sizeof( mbedtls_ssl_session ) ); +#if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_CLI_C) + dst->ticket = NULL; +#endif + #if defined(MBEDTLS_X509_CRT_PARSE_C) if( src->peer_cert != NULL ) { -- Gitee