diff options
author | doug <> | 2015-06-13 08:46:00 +0000 |
---|---|---|
committer | doug <> | 2015-06-13 08:46:00 +0000 |
commit | 7f7999bf62a2909a02c91df3194a58221ef505e1 (patch) | |
tree | 1dc64559a73ae21e3c8c80b0306238fcccc7bc28 /src | |
parent | a3f6270cf947329be3b9091ddfdbab704042addd (diff) | |
download | openbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.tar.gz openbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.tar.bz2 openbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.zip |
Reject long-form tags in CBS_peek_asn1_tag.
Currently, CBS only handles short-form tags.
ok miod@ jsing@
Diffstat (limited to 'src')
-rw-r--r-- | src/lib/libssl/bs_cbs.c | 9 | ||||
-rw-r--r-- | src/lib/libssl/src/ssl/bs_cbs.c | 9 |
2 files changed, 16 insertions, 2 deletions
diff --git a/src/lib/libssl/bs_cbs.c b/src/lib/libssl/bs_cbs.c index 4c1bfa3288..c37f81dd60 100644 --- a/src/lib/libssl/bs_cbs.c +++ b/src/lib/libssl/bs_cbs.c | |||
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: bs_cbs.c,v 1.7 2015/04/29 02:11:09 doug Exp $ */ | 1 | /* $OpenBSD: bs_cbs.c,v 1.8 2015/06/13 08:46:00 doug Exp $ */ |
2 | /* | 2 | /* |
3 | * Copyright (c) 2014, Google Inc. | 3 | * Copyright (c) 2014, Google Inc. |
4 | * | 4 | * |
@@ -314,6 +314,13 @@ CBS_peek_asn1_tag(const CBS *cbs, unsigned tag_value) | |||
314 | if (CBS_len(cbs) < 1) | 314 | if (CBS_len(cbs) < 1) |
315 | return 0; | 315 | return 0; |
316 | 316 | ||
317 | /* | ||
318 | * Tag number 31 indicates the start of a long form number. | ||
319 | * This is valid in ASN.1, but CBS only supports short form. | ||
320 | */ | ||
321 | if ((tag_value & 0x1f) == 0x1f) | ||
322 | return 0; | ||
323 | |||
317 | return CBS_data(cbs)[0] == tag_value; | 324 | return CBS_data(cbs)[0] == tag_value; |
318 | } | 325 | } |
319 | 326 | ||
diff --git a/src/lib/libssl/src/ssl/bs_cbs.c b/src/lib/libssl/src/ssl/bs_cbs.c index 4c1bfa3288..c37f81dd60 100644 --- a/src/lib/libssl/src/ssl/bs_cbs.c +++ b/src/lib/libssl/src/ssl/bs_cbs.c | |||
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: bs_cbs.c,v 1.7 2015/04/29 02:11:09 doug Exp $ */ | 1 | /* $OpenBSD: bs_cbs.c,v 1.8 2015/06/13 08:46:00 doug Exp $ */ |
2 | /* | 2 | /* |
3 | * Copyright (c) 2014, Google Inc. | 3 | * Copyright (c) 2014, Google Inc. |
4 | * | 4 | * |
@@ -314,6 +314,13 @@ CBS_peek_asn1_tag(const CBS *cbs, unsigned tag_value) | |||
314 | if (CBS_len(cbs) < 1) | 314 | if (CBS_len(cbs) < 1) |
315 | return 0; | 315 | return 0; |
316 | 316 | ||
317 | /* | ||
318 | * Tag number 31 indicates the start of a long form number. | ||
319 | * This is valid in ASN.1, but CBS only supports short form. | ||
320 | */ | ||
321 | if ((tag_value & 0x1f) == 0x1f) | ||
322 | return 0; | ||
323 | |||
317 | return CBS_data(cbs)[0] == tag_value; | 324 | return CBS_data(cbs)[0] == tag_value; |
318 | } | 325 | } |
319 | 326 | ||