diff options
| author | jsing <> | 2018-08-14 16:19:06 +0000 | 
|---|---|---|
| committer | jsing <> | 2018-08-14 16:19:06 +0000 | 
| commit | 288abfc36cecbcfd9ea6764f060a9329f865ad28 (patch) | |
| tree | 6412a5127a983ac896f0ea63ec3754e25b4eee8d /src/lib/libssl/ssl_clnt.c | |
| parent | fd0fe048aba73cca22d3220f299f765d414cb211 (diff) | |
| download | openbsd-288abfc36cecbcfd9ea6764f060a9329f865ad28.tar.gz openbsd-288abfc36cecbcfd9ea6764f060a9329f865ad28.tar.bz2 openbsd-288abfc36cecbcfd9ea6764f060a9329f865ad28.zip  | |
Actually check the return values for EVP_Sign* and EVP_Verify*.
ok bcook@ beck@ tb@
Diffstat (limited to '')
| -rw-r--r-- | src/lib/libssl/ssl_clnt.c | 20 | 
1 files changed, 12 insertions, 8 deletions
diff --git a/src/lib/libssl/ssl_clnt.c b/src/lib/libssl/ssl_clnt.c index f9cdd8657a..dcd4da3634 100644 --- a/src/lib/libssl/ssl_clnt.c +++ b/src/lib/libssl/ssl_clnt.c  | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: ssl_clnt.c,v 1.27 2018/08/10 17:52:35 jsing Exp $ */ | 1 | /* $OpenBSD: ssl_clnt.c,v 1.28 2018/08/14 16:19:06 jsing Exp $ */ | 
| 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 
| 3 | * All rights reserved. | 3 | * All rights reserved. | 
| 4 | * | 4 | * | 
| @@ -1553,13 +1553,17 @@ ssl3_get_server_key_exchange(SSL *s) | |||
| 1553 | goto f_err; | 1553 | goto f_err; | 
| 1554 | } | 1554 | } | 
| 1555 | 1555 | ||
| 1556 | EVP_VerifyInit_ex(&md_ctx, md, NULL); | 1556 | if (!EVP_VerifyInit_ex(&md_ctx, md, NULL)) | 
| 1557 | EVP_VerifyUpdate(&md_ctx, s->s3->client_random, | 1557 | goto err; | 
| 1558 | SSL3_RANDOM_SIZE); | 1558 | if (!EVP_VerifyUpdate(&md_ctx, s->s3->client_random, | 
| 1559 | EVP_VerifyUpdate(&md_ctx, s->s3->server_random, | 1559 | SSL3_RANDOM_SIZE)) | 
| 1560 | SSL3_RANDOM_SIZE); | 1560 | goto err; | 
| 1561 | EVP_VerifyUpdate(&md_ctx, param, param_len); | 1561 | if (!EVP_VerifyUpdate(&md_ctx, s->s3->server_random, | 
| 1562 | if (EVP_VerifyFinal(&md_ctx, p,(int)n, pkey) <= 0) { | 1562 | SSL3_RANDOM_SIZE)) | 
| 1563 | goto err; | ||
| 1564 | if (!EVP_VerifyUpdate(&md_ctx, param, param_len)) | ||
| 1565 | goto err; | ||
| 1566 | if (EVP_VerifyFinal(&md_ctx, p, (int)n, pkey) <= 0) { | ||
| 1563 | /* bad signature */ | 1567 | /* bad signature */ | 
| 1564 | al = SSL_AD_DECRYPT_ERROR; | 1568 | al = SSL_AD_DECRYPT_ERROR; | 
| 1565 | SSLerror(s, SSL_R_BAD_SIGNATURE); | 1569 | SSLerror(s, SSL_R_BAD_SIGNATURE); | 
