[tls] Guard against a premature server Finished A malicious server that immediately sends a Finished record (without ever having sent a ServerHello) will currently cause tls_prf() to get stuck in an infinite loop attempting to generate pseudorandom data using the null digest algorithm. Fix by checking that the key schedule digest size is non-zero (i.e. that the digest is not the null digest) before attempting to process the Finished record. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
boot from a web server via HTTP or HTTPS,
boot from an iSCSI, FCoE, or AoE SAN,
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.