Check max_out against in_len, not plaintext_len in RC4/MD5 AEAD.

Like the non-stitched variant, this "AEAD" uses the output buffer as
scratch space for the MAC. Thus it should require that max_out_len is
large enough to fit that, even though it will never return that large of

Change-Id: I5b30b0756408c2e433448f540e7c65251336d2f8
Reviewed-by: Adam Langley <>
1 file changed