mirror of
				https://github.com/cuberite/polarssl.git
				synced 2025-11-04 04:32:24 -05:00 
			
		
		
		
	Included test for integer underflow.
This commit is contained in:
		
							parent
							
								
									edb1a48397
								
							
						
					
					
						commit
						b8afe1bb2c
					
				@ -720,6 +720,10 @@ int mbedtls_rsa_rsaes_oaep_decrypt( mbedtls_rsa_context *ctx,
 | 
				
			|||||||
     */
 | 
					     */
 | 
				
			||||||
    hlen = mbedtls_md_get_size( md_info );
 | 
					    hlen = mbedtls_md_get_size( md_info );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					    // checking for integer underflow
 | 
				
			||||||
 | 
					    if( 2 * hlen + 2 > ilen )
 | 
				
			||||||
 | 
					        return( MBEDTLS_ERR_RSA_BAD_INPUT_DATA );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    mbedtls_md_init( &md_ctx );
 | 
					    mbedtls_md_init( &md_ctx );
 | 
				
			||||||
    mbedtls_md_setup( &md_ctx, md_info, 0 );
 | 
					    mbedtls_md_setup( &md_ctx, md_info, 0 );
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
				
			|||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user