RFR: 8299870: TLS record version check allows invalid records [v4]
Rajan Halade
rhalade at openjdk.org
Thu Jan 19 19:02:26 UTC 2023
On Tue, 17 Jan 2023 17:12:05 GMT, Matthew Donovan <duke at openjdk.org> wrote:
>> - Updated ProtocolVersion.isNegotiable() to check a bounded range of version numbers.
>> - Removed IllegalRecordVersion.java from ProblemList.txt
>>
>> Tested with jdk_security and jdk_security3 test groups.
>
> Matthew Donovan has updated the pull request incrementally with one additional commit since the last revision:
>
> removed extra whitespace
Thinking may be it is better to close JDK-8299870 and "Not an Issue" for archival purpose and address the test fix as part of JDK-8298873. What do you think?
-------------
PR: https://git.openjdk.org/jdk/pull/11929
More information about the security-dev
mailing list