diff options
author | Nikos Mavrogiannopoulos <nmav@redhat.com> | 2015-04-20 14:56:27 +0200 |
---|---|---|
committer | Nikos Mavrogiannopoulos <nmav@redhat.com> | 2015-04-20 14:56:38 +0200 |
commit | f979435823a02f842c41d49cd41cc81f25b5d677 (patch) | |
tree | b633dbee445a03b39db6269641666716564fa15d | |
parent | bf69ce965a724f3bd730716143a67b800836416b (diff) | |
download | libtasn1-f979435823a02f842c41d49cd41cc81f25b5d677.tar.gz |
_asn1_extract_der_octet: prevent past of boundary access
Reported by Hanno Böck.
-rw-r--r-- | lib/decoding.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/lib/decoding.c b/lib/decoding.c index 7fbd931..42ddc6b 100644 --- a/lib/decoding.c +++ b/lib/decoding.c @@ -732,6 +732,7 @@ _asn1_extract_der_octet (asn1_node node, const unsigned char *der, return ASN1_DER_ERROR; counter = len3 + 1; + DECR_LEN(der_len, len3); if (len2 == -1) counter_end = der_len - 2; @@ -740,6 +741,7 @@ _asn1_extract_der_octet (asn1_node node, const unsigned char *der, while (counter < counter_end) { + DECR_LEN(der_len, 1); len2 = asn1_get_length_der (der + counter, der_len, &len3); if (IS_ERR(len2, flags)) @@ -764,7 +766,6 @@ _asn1_extract_der_octet (asn1_node node, const unsigned char *der, len2 = 0; } - DECR_LEN(der_len, 1); counter += len2 + len3 + 1; } |