Sanity length checks in ssl_read_record() and ssl_fetch_input()

Both are already covered in other places, but not in a clear fashion. So
for instance Coverity thinks the value is still tainted.
1 file changed