From 7e2af3d74b54905003aaf02b5aa4117cb1177194 Mon Sep 17 00:00:00 2001 From: Nikos Mavrogiannopoulos Date: Sun, 6 Jul 2014 22:58:42 +0200 Subject: dane: Added sanity check in dane_verify_crt_raw() That allows calling the function will an empty chain. Reported by Simon Arlott. --- libdane/dane.c | 3 +++ 1 file changed, 3 insertions(+) (limited to 'libdane') diff --git a/libdane/dane.c b/libdane/dane.c index 50e6dd03eb..88a0b8b4a9 100644 --- a/libdane/dane.c +++ b/libdane/dane.c @@ -646,6 +646,9 @@ dane_verify_crt_raw(dane_state_t s, if (chain_type != GNUTLS_CRT_X509) return gnutls_assert_val(DANE_E_INVALID_REQUEST); + if (chain_size == 0) + return gnutls_assert_val(DANE_E_NO_CERT); + *verify = 0; idx = 0; do { -- cgit v1.2.1