summaryrefslogtreecommitdiffstats
path: root/lib/libssl/bs_cbs.c
diff options
context:
space:
mode:
authordoug <doug@openbsd.org>2015-06-13 08:46:00 +0000
committerdoug <doug@openbsd.org>2015-06-13 08:46:00 +0000
commit0e95035f4b9fd86b7ab5709c4bf0e550a0dd75a5 (patch)
tree725f5a26ed689ee1e3f39f1275abbe0f0f5518db /lib/libssl/bs_cbs.c
parentFix bad indenting in LibreSSL. (diff)
downloadwireguard-openbsd-0e95035f4b9fd86b7ab5709c4bf0e550a0dd75a5.tar.xz
wireguard-openbsd-0e95035f4b9fd86b7ab5709c4bf0e550a0dd75a5.zip
Reject long-form tags in CBS_peek_asn1_tag.
Currently, CBS only handles short-form tags. ok miod@ jsing@
Diffstat (limited to 'lib/libssl/bs_cbs.c')
-rw-r--r--lib/libssl/bs_cbs.c9
1 files changed, 8 insertions, 1 deletions
diff --git a/lib/libssl/bs_cbs.c b/lib/libssl/bs_cbs.c
index 4c1bfa32881..c37f81dd60f 100644
--- a/lib/libssl/bs_cbs.c
+++ b/lib/libssl/bs_cbs.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: bs_cbs.c,v 1.7 2015/04/29 02:11:09 doug Exp $ */
+/* $OpenBSD: bs_cbs.c,v 1.8 2015/06/13 08:46:00 doug Exp $ */
/*
* Copyright (c) 2014, Google Inc.
*
@@ -314,6 +314,13 @@ CBS_peek_asn1_tag(const CBS *cbs, unsigned tag_value)
if (CBS_len(cbs) < 1)
return 0;
+ /*
+ * Tag number 31 indicates the start of a long form number.
+ * This is valid in ASN.1, but CBS only supports short form.
+ */
+ if ((tag_value & 0x1f) == 0x1f)
+ return 0;
+
return CBS_data(cbs)[0] == tag_value;
}