In ssl3_get_client_certificate, ssl3_get_server_certificate and ssl3_get_certificate_request check we have enough room before reading a length. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6306