Fix ASN1_TYPE_cmp
Fix segmentation violation when ASN1_TYPE_cmp is passed a boolean type. This can be triggered during certificate verification so could be a DoS attack against a client or a server enabling client authentication. CVE-2015-0286 Reviewed-by: Richard Levitte <levitte@openssl.org>
This commit is contained in:
parent
b19d814321
commit
c3c7fb07dc
@ -119,6 +119,9 @@ int ASN1_TYPE_cmp(const ASN1_TYPE *a, const ASN1_TYPE *b)
|
|||||||
case V_ASN1_OBJECT:
|
case V_ASN1_OBJECT:
|
||||||
result = OBJ_cmp(a->value.object, b->value.object);
|
result = OBJ_cmp(a->value.object, b->value.object);
|
||||||
break;
|
break;
|
||||||
|
case V_ASN1_BOOLEAN:
|
||||||
|
result = a->value.boolean - b->value.boolean;
|
||||||
|
break;
|
||||||
case V_ASN1_NULL:
|
case V_ASN1_NULL:
|
||||||
result = 0; /* They do not have content. */
|
result = 0; /* They do not have content. */
|
||||||
break;
|
break;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user