summaryrefslogtreecommitdiffstats
path: root/crypto/cmac
diff options
context:
space:
mode:
authorHanno Böck <hanno@hboeck.de>2015-05-11 11:33:37 +0100
committerMatt Caswell <matt@openssl.org>2015-05-13 15:23:57 +0100
commit2b8dc08b74fc3c6d4c2fc855cc23bac691d985be (patch)
tree5ace6bdeee218949e1c49ca04d8cbddee7a8afad /crypto/cmac
parentc3d734701cd57575856bf9b542446811518dd28c (diff)
Call of memcmp with null pointers in obj_cmp()
The function obj_cmp() (file crypto/objects/obj_dat.c) can in some situations call memcmp() with a null pointer and a zero length. This is invalid behaviour. When compiling openssl with undefined behaviour sanitizer (add -fsanitize=undefined to compile flags) this can be seen. One example that triggers this behaviour is the pkcs7 command (but there are others, e.g. I've seen it with the timestamp function): apps/openssl pkcs7 -in test/testp7.pem What happens is that obj_cmp takes objects of the type ASN1_OBJECT and passes their ->data pointer to memcmp. Zero-sized ASN1_OBJECT structures can have a null pointer as data. RT#3816 Signed-off-by: Matt Caswell <matt@openssl.org> Reviewed-by: Rich Salz <rsalz@openssl.org>
Diffstat (limited to 'crypto/cmac')
0 files changed, 0 insertions, 0 deletions