diff options
author | schwarze <> | 2020-06-04 21:21:03 +0000 |
---|---|---|
committer | schwarze <> | 2020-06-04 21:21:03 +0000 |
commit | d0cf9aeca512581235a63d9ed8e8a3c69039b9df (patch) | |
tree | 2920ef908eabfe843f01bfd04a3aaf4eff0a1cec /src/lib | |
parent | 53beb8fe96aa9ab3ce5c57b525e3a1fbb817382e (diff) | |
download | openbsd-d0cf9aeca512581235a63d9ed8e8a3c69039b9df.tar.gz openbsd-d0cf9aeca512581235a63d9ed8e8a3c69039b9df.tar.bz2 openbsd-d0cf9aeca512581235a63d9ed8e8a3c69039b9df.zip |
When X509_ATTRIBUTE_create() receives an invalid NID (e.g., -1), return
failure rather than silently constructing a broken X509_ATTRIBUTE object
that might cause NULL pointer accesses later on. This matters because
X509_ATTRIBUTE_create() is used by documented API functions like
PKCS7_add_attribute(3) and the NID comes straight from the user.
This fixes a bug found while working on documentation.
OK tb@ and "thanks" bluhm@
Diffstat (limited to 'src/lib')
-rw-r--r-- | src/lib/libcrypto/asn1/x_attrib.c | 7 | ||||
-rw-r--r-- | src/lib/libcrypto/man/PKCS7_add_attribute.3 | 16 |
2 files changed, 9 insertions, 14 deletions
diff --git a/src/lib/libcrypto/asn1/x_attrib.c b/src/lib/libcrypto/asn1/x_attrib.c index bb74a1b6c7..04816eab77 100644 --- a/src/lib/libcrypto/asn1/x_attrib.c +++ b/src/lib/libcrypto/asn1/x_attrib.c | |||
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: x_attrib.c,v 1.13 2015/02/14 14:56:45 jsing Exp $ */ | 1 | /* $OpenBSD: x_attrib.c,v 1.14 2020/06/04 21:21:03 schwarze Exp $ */ |
2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) |
3 | * All rights reserved. | 3 | * All rights reserved. |
4 | * | 4 | * |
@@ -174,10 +174,13 @@ X509_ATTRIBUTE_create(int nid, int atrtype, void *value) | |||
174 | { | 174 | { |
175 | X509_ATTRIBUTE *ret = NULL; | 175 | X509_ATTRIBUTE *ret = NULL; |
176 | ASN1_TYPE *val = NULL; | 176 | ASN1_TYPE *val = NULL; |
177 | ASN1_OBJECT *oid; | ||
177 | 178 | ||
179 | if ((oid = OBJ_nid2obj(nid)) == NULL) | ||
180 | return (NULL); | ||
178 | if ((ret = X509_ATTRIBUTE_new()) == NULL) | 181 | if ((ret = X509_ATTRIBUTE_new()) == NULL) |
179 | return (NULL); | 182 | return (NULL); |
180 | ret->object = OBJ_nid2obj(nid); | 183 | ret->object = oid; |
181 | ret->single = 0; | 184 | ret->single = 0; |
182 | if ((ret->value.set = sk_ASN1_TYPE_new_null()) == NULL) | 185 | if ((ret->value.set = sk_ASN1_TYPE_new_null()) == NULL) |
183 | goto err; | 186 | goto err; |
diff --git a/src/lib/libcrypto/man/PKCS7_add_attribute.3 b/src/lib/libcrypto/man/PKCS7_add_attribute.3 index 09c36a4d5d..081703f0f3 100644 --- a/src/lib/libcrypto/man/PKCS7_add_attribute.3 +++ b/src/lib/libcrypto/man/PKCS7_add_attribute.3 | |||
@@ -1,4 +1,4 @@ | |||
1 | .\" $OpenBSD: PKCS7_add_attribute.3,v 1.1 2020/06/04 10:24:27 schwarze Exp $ | 1 | .\" $OpenBSD: PKCS7_add_attribute.3,v 1.2 2020/06/04 21:21:03 schwarze Exp $ |
2 | .\" | 2 | .\" |
3 | .\" Copyright (c) 2020 Ingo Schwarze <schwarze@openbsd.org> | 3 | .\" Copyright (c) 2020 Ingo Schwarze <schwarze@openbsd.org> |
4 | .\" | 4 | .\" |
@@ -123,7 +123,9 @@ exist. | |||
123 | and | 123 | and |
124 | .Fn PKCS7_add_signed_attribute | 124 | .Fn PKCS7_add_signed_attribute |
125 | return 1 on success or 0 on failure. | 125 | return 1 on success or 0 on failure. |
126 | The most common reason for failure is lack of memory. | 126 | The most common reasons for failure are an invalid |
127 | .Fa nid | ||
128 | argument or lack of memory. | ||
127 | .Pp | 129 | .Pp |
128 | .Fn PKCS7_get_attribute | 130 | .Fn PKCS7_get_attribute |
129 | and | 131 | and |
@@ -153,16 +155,6 @@ These functions first appeared in OpenSSL 0.9.1 | |||
153 | and have been available since | 155 | and have been available since |
154 | .Ox 2.6 . | 156 | .Ox 2.6 . |
155 | .Sh BUGS | 157 | .Sh BUGS |
156 | Adding an attribute with an invalid | ||
157 | .Fa nid | ||
158 | ought to fail, but it actually succeeds | ||
159 | setting the type of the new attribute to | ||
160 | .Dv NULL . | ||
161 | Subsequent attempts to retrieve attributes | ||
162 | may cause the program to crash due to | ||
163 | .Dv NULL | ||
164 | pointer access. | ||
165 | .Pp | ||
166 | A function to remove individual attributes from these lists | 158 | A function to remove individual attributes from these lists |
167 | does not appear to exist. | 159 | does not appear to exist. |
168 | A program desiring to do that might have to manually iterate the fields | 160 | A program desiring to do that might have to manually iterate the fields |