mirror of
https://github.com/QuasarApp/openssl.git
synced 2025-05-14 10:29:42 +00:00
Add checks to X509_NAME_oneline()
Sanity check field lengths and sums to avoid potential overflows and reject excessively large X509_NAME structures. Issue reported by Guido Vranken. Reviewed-by: Matt Caswell <matt@openssl.org>
This commit is contained in:
parent
b33d1141b6
commit
77076dc944
@ -1,56 +1,11 @@
|
|||||||
/* ====================================================================
|
/*
|
||||||
* Copyright (c) 1999-2016 The OpenSSL Project. All rights reserved.
|
* Copyright 1995-2016 The OpenSSL Project Authors. All Rights Reserved.
|
||||||
*
|
*
|
||||||
* Redistribution and use in source and binary forms, with or without
|
* Licensed under the OpenSSL license (the "License"). You may not use
|
||||||
* modification, are permitted provided that the following conditions
|
* this file except in compliance with the License. You can obtain a copy
|
||||||
* are met:
|
* in the file LICENSE in the source distribution or at
|
||||||
*
|
* https://www.openssl.org/source/license.html
|
||||||
* 1. Redistributions of source code must retain the above copyright
|
*/
|
||||||
* notice, this list of conditions and the following disclaimer.
|
|
||||||
*
|
|
||||||
* 2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
* notice, this list of conditions and the following disclaimer in
|
|
||||||
* the documentation and/or other materials provided with the
|
|
||||||
* distribution.
|
|
||||||
*
|
|
||||||
* 3. All advertising materials mentioning features or use of this
|
|
||||||
* software must display the following acknowledgment:
|
|
||||||
* "This product includes software developed by the OpenSSL Project
|
|
||||||
* for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
|
|
||||||
*
|
|
||||||
* 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
|
|
||||||
* endorse or promote products derived from this software without
|
|
||||||
* prior written permission. For written permission, please contact
|
|
||||||
* openssl-core@OpenSSL.org.
|
|
||||||
*
|
|
||||||
* 5. Products derived from this software may not be called "OpenSSL"
|
|
||||||
* nor may "OpenSSL" appear in their names without prior written
|
|
||||||
* permission of the OpenSSL Project.
|
|
||||||
*
|
|
||||||
* 6. Redistributions of any form whatsoever must retain the following
|
|
||||||
* acknowledgment:
|
|
||||||
* "This product includes software developed by the OpenSSL Project
|
|
||||||
* for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
|
|
||||||
*
|
|
||||||
* THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
|
|
||||||
* EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
|
||||||
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
|
|
||||||
* ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
||||||
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
||||||
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
|
|
||||||
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
||||||
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
|
||||||
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
|
||||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
|
||||||
* OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
||||||
* ====================================================================
|
|
||||||
*
|
|
||||||
* This product includes cryptographic software written by Eric Young
|
|
||||||
* (eay@cryptsoft.com). This product includes software written by Tim
|
|
||||||
* Hudson (tjh@cryptsoft.com).
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* NOTE: this file was auto generated by the mkerr.pl script: any changes
|
* NOTE: this file was auto generated by the mkerr.pl script: any changes
|
||||||
@ -156,6 +111,7 @@ static ERR_STRING_DATA X509_str_reasons[] = {
|
|||||||
{ERR_REASON(X509_R_LOADING_CERT_DIR), "loading cert dir"},
|
{ERR_REASON(X509_R_LOADING_CERT_DIR), "loading cert dir"},
|
||||||
{ERR_REASON(X509_R_LOADING_DEFAULTS), "loading defaults"},
|
{ERR_REASON(X509_R_LOADING_DEFAULTS), "loading defaults"},
|
||||||
{ERR_REASON(X509_R_METHOD_NOT_SUPPORTED), "method not supported"},
|
{ERR_REASON(X509_R_METHOD_NOT_SUPPORTED), "method not supported"},
|
||||||
|
{ERR_REASON(X509_R_NAME_TOO_LONG), "name too long"},
|
||||||
{ERR_REASON(X509_R_NEWER_CRL_NOT_NEWER), "newer crl not newer"},
|
{ERR_REASON(X509_R_NEWER_CRL_NOT_NEWER), "newer crl not newer"},
|
||||||
{ERR_REASON(X509_R_NO_CERT_SET_FOR_US_TO_VERIFY),
|
{ERR_REASON(X509_R_NO_CERT_SET_FOR_US_TO_VERIFY),
|
||||||
"no cert set for us to verify"},
|
"no cert set for us to verify"},
|
||||||
|
@ -63,6 +63,13 @@
|
|||||||
#include <openssl/buffer.h>
|
#include <openssl/buffer.h>
|
||||||
#include "internal/x509_int.h"
|
#include "internal/x509_int.h"
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Limit to ensure we don't overflow: much greater than
|
||||||
|
* anything enountered in practice.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#define NAME_ONELINE_MAX (1024 * 1024)
|
||||||
|
|
||||||
char *X509_NAME_oneline(X509_NAME *a, char *buf, int len)
|
char *X509_NAME_oneline(X509_NAME *a, char *buf, int len)
|
||||||
{
|
{
|
||||||
X509_NAME_ENTRY *ne;
|
X509_NAME_ENTRY *ne;
|
||||||
@ -112,6 +119,10 @@ char *X509_NAME_oneline(X509_NAME *a, char *buf, int len)
|
|||||||
|
|
||||||
type = ne->value->type;
|
type = ne->value->type;
|
||||||
num = ne->value->length;
|
num = ne->value->length;
|
||||||
|
if (num > NAME_ONELINE_MAX) {
|
||||||
|
X509err(X509_F_X509_NAME_ONELINE, X509_R_NAME_TOO_LONG);
|
||||||
|
goto end;
|
||||||
|
}
|
||||||
q = ne->value->data;
|
q = ne->value->data;
|
||||||
#ifdef CHARSET_EBCDIC
|
#ifdef CHARSET_EBCDIC
|
||||||
if (type == V_ASN1_GENERALSTRING ||
|
if (type == V_ASN1_GENERALSTRING ||
|
||||||
@ -156,6 +167,10 @@ char *X509_NAME_oneline(X509_NAME *a, char *buf, int len)
|
|||||||
|
|
||||||
lold = l;
|
lold = l;
|
||||||
l += 1 + l1 + 1 + l2;
|
l += 1 + l1 + 1 + l2;
|
||||||
|
if (l > NAME_ONELINE_MAX) {
|
||||||
|
X509err(X509_F_X509_NAME_ONELINE, X509_R_NAME_TOO_LONG);
|
||||||
|
goto end;
|
||||||
|
}
|
||||||
if (b != NULL) {
|
if (b != NULL) {
|
||||||
if (!BUF_MEM_grow(b, l + 1))
|
if (!BUF_MEM_grow(b, l + 1))
|
||||||
goto err;
|
goto err;
|
||||||
@ -208,6 +223,7 @@ char *X509_NAME_oneline(X509_NAME *a, char *buf, int len)
|
|||||||
return (p);
|
return (p);
|
||||||
err:
|
err:
|
||||||
X509err(X509_F_X509_NAME_ONELINE, ERR_R_MALLOC_FAILURE);
|
X509err(X509_F_X509_NAME_ONELINE, ERR_R_MALLOC_FAILURE);
|
||||||
|
end:
|
||||||
BUF_MEM_free(b);
|
BUF_MEM_free(b);
|
||||||
return (NULL);
|
return (NULL);
|
||||||
}
|
}
|
||||||
|
@ -1122,6 +1122,7 @@ void ERR_load_X509_strings(void);
|
|||||||
# define X509_R_LOADING_CERT_DIR 103
|
# define X509_R_LOADING_CERT_DIR 103
|
||||||
# define X509_R_LOADING_DEFAULTS 104
|
# define X509_R_LOADING_DEFAULTS 104
|
||||||
# define X509_R_METHOD_NOT_SUPPORTED 124
|
# define X509_R_METHOD_NOT_SUPPORTED 124
|
||||||
|
# define X509_R_NAME_TOO_LONG 134
|
||||||
# define X509_R_NEWER_CRL_NOT_NEWER 132
|
# define X509_R_NEWER_CRL_NOT_NEWER 132
|
||||||
# define X509_R_NO_CERT_SET_FOR_US_TO_VERIFY 105
|
# define X509_R_NO_CERT_SET_FOR_US_TO_VERIFY 105
|
||||||
# define X509_R_NO_CRL_NUMBER 130
|
# define X509_R_NO_CRL_NUMBER 130
|
||||||
|
Loading…
x
Reference in New Issue
Block a user