diff options
| author | tb <> | 2021-12-26 15:10:59 +0000 |
|---|---|---|
| committer | tb <> | 2021-12-26 15:10:59 +0000 |
| commit | a2d5fa10de4afe08bd921a797a3634815bf0f460 (patch) | |
| tree | 9904bf7ffa9ad2af2073419c5dcad5811c813383 /src | |
| parent | 7f97a389979014d8bd25ff0a6e61a99fcf0d699a (diff) | |
| download | openbsd-a2d5fa10de4afe08bd921a797a3634815bf0f460.tar.gz openbsd-a2d5fa10de4afe08bd921a797a3634815bf0f460.tar.bz2 openbsd-a2d5fa10de4afe08bd921a797a3634815bf0f460.zip | |
Hoist memset of CBB above EVP_MD_CTX_new() and HMAC_CTX_new() to avoid
a use of uninitialized in the unlikely event that either of them fails.
Problem introduced in r1.128.
CID 345113
ok jsing
Diffstat (limited to 'src')
| -rw-r--r-- | src/lib/libssl/ssl_srvr.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/src/lib/libssl/ssl_srvr.c b/src/lib/libssl/ssl_srvr.c index 665fcc5037..330f9176d8 100644 --- a/src/lib/libssl/ssl_srvr.c +++ b/src/lib/libssl/ssl_srvr.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: ssl_srvr.c,v 1.128 2021/12/09 17:53:29 tb Exp $ */ | 1 | /* $OpenBSD: ssl_srvr.c,v 1.129 2021/12/26 15:10:59 tb Exp $ */ |
| 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) |
| 3 | * All rights reserved. | 3 | * All rights reserved. |
| 4 | * | 4 | * |
| @@ -2494,13 +2494,13 @@ ssl3_send_newsession_ticket(SSL *s) | |||
| 2494 | * New Session Ticket - RFC 5077, section 3.3. | 2494 | * New Session Ticket - RFC 5077, section 3.3. |
| 2495 | */ | 2495 | */ |
| 2496 | 2496 | ||
| 2497 | memset(&cbb, 0, sizeof(cbb)); | ||
| 2498 | |||
| 2497 | if ((ctx = EVP_CIPHER_CTX_new()) == NULL) | 2499 | if ((ctx = EVP_CIPHER_CTX_new()) == NULL) |
| 2498 | goto err; | 2500 | goto err; |
| 2499 | if ((hctx = HMAC_CTX_new()) == NULL) | 2501 | if ((hctx = HMAC_CTX_new()) == NULL) |
| 2500 | goto err; | 2502 | goto err; |
| 2501 | 2503 | ||
| 2502 | memset(&cbb, 0, sizeof(cbb)); | ||
| 2503 | |||
| 2504 | if (S3I(s)->hs.state == SSL3_ST_SW_SESSION_TICKET_A) { | 2504 | if (S3I(s)->hs.state == SSL3_ST_SW_SESSION_TICKET_A) { |
| 2505 | if (!ssl3_handshake_msg_start(s, &cbb, &session_ticket, | 2505 | if (!ssl3_handshake_msg_start(s, &cbb, &session_ticket, |
| 2506 | SSL3_MT_NEWSESSION_TICKET)) | 2506 | SSL3_MT_NEWSESSION_TICKET)) |
