summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authordoug <>2015-06-13 08:46:00 +0000
committerdoug <>2015-06-13 08:46:00 +0000
commit7f7999bf62a2909a02c91df3194a58221ef505e1 (patch)
tree1dc64559a73ae21e3c8c80b0306238fcccc7bc28 /src
parenta3f6270cf947329be3b9091ddfdbab704042addd (diff)
downloadopenbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.tar.gz
openbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.tar.bz2
openbsd-7f7999bf62a2909a02c91df3194a58221ef505e1.zip
Reject long-form tags in CBS_peek_asn1_tag.
Currently, CBS only handles short-form tags. ok miod@ jsing@
Diffstat (limited to 'src')
-rw-r--r--src/lib/libssl/bs_cbs.c9
-rw-r--r--src/lib/libssl/src/ssl/bs_cbs.c9
2 files changed, 16 insertions, 2 deletions
diff --git a/src/lib/libssl/bs_cbs.c b/src/lib/libssl/bs_cbs.c
index 4c1bfa3288..c37f81dd60 100644
--- a/src/lib/libssl/bs_cbs.c
+++ b/src/lib/libssl/bs_cbs.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: bs_cbs.c,v 1.7 2015/04/29 02:11:09 doug Exp $ */ 1/* $OpenBSD: bs_cbs.c,v 1.8 2015/06/13 08:46:00 doug Exp $ */
2/* 2/*
3 * Copyright (c) 2014, Google Inc. 3 * Copyright (c) 2014, Google Inc.
4 * 4 *
@@ -314,6 +314,13 @@ CBS_peek_asn1_tag(const CBS *cbs, unsigned tag_value)
314 if (CBS_len(cbs) < 1) 314 if (CBS_len(cbs) < 1)
315 return 0; 315 return 0;
316 316
317 /*
318 * Tag number 31 indicates the start of a long form number.
319 * This is valid in ASN.1, but CBS only supports short form.
320 */
321 if ((tag_value & 0x1f) == 0x1f)
322 return 0;
323
317 return CBS_data(cbs)[0] == tag_value; 324 return CBS_data(cbs)[0] == tag_value;
318} 325}
319 326
diff --git a/src/lib/libssl/src/ssl/bs_cbs.c b/src/lib/libssl/src/ssl/bs_cbs.c
index 4c1bfa3288..c37f81dd60 100644
--- a/src/lib/libssl/src/ssl/bs_cbs.c
+++ b/src/lib/libssl/src/ssl/bs_cbs.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: bs_cbs.c,v 1.7 2015/04/29 02:11:09 doug Exp $ */ 1/* $OpenBSD: bs_cbs.c,v 1.8 2015/06/13 08:46:00 doug Exp $ */
2/* 2/*
3 * Copyright (c) 2014, Google Inc. 3 * Copyright (c) 2014, Google Inc.
4 * 4 *
@@ -314,6 +314,13 @@ CBS_peek_asn1_tag(const CBS *cbs, unsigned tag_value)
314 if (CBS_len(cbs) < 1) 314 if (CBS_len(cbs) < 1)
315 return 0; 315 return 0;
316 316
317 /*
318 * Tag number 31 indicates the start of a long form number.
319 * This is valid in ASN.1, but CBS only supports short form.
320 */
321 if ((tag_value & 0x1f) == 0x1f)
322 return 0;
323
317 return CBS_data(cbs)[0] == tag_value; 324 return CBS_data(cbs)[0] == tag_value;
318} 325}
319 326