Pārlūkot izejas kodu

OCBv3: better taglen limitation

Steffen Jaeckel 8 gadi atpakaļ
vecāks
revīzija
3ecd18763b
1 mainītis faili ar 4 papildinājumiem un 1 dzēšanām
  1. 4 1
      src/encauth/ocb3/ocb3_decrypt_verify_memory.c

+ 4 - 1
src/encauth/ocb3/ocb3_decrypt_verify_memory.c

@@ -51,8 +51,11 @@ int ocb3_decrypt_verify_memory(int cipher,
    /* default to zero */
    /* default to zero */
    *stat = 0;
    *stat = 0;
 
 
+   /* limit taglen */
+   taglen = MIN(taglen, MAXBLOCKSIZE);
+
    /* allocate memory */
    /* allocate memory */
-   buf = XMALLOC(MIN(taglen, MAXBLOCKSIZE));
+   buf = XMALLOC(taglen);
    ocb = XMALLOC(sizeof(ocb3_state));
    ocb = XMALLOC(sizeof(ocb3_state));
    if (ocb == NULL || buf == NULL) {
    if (ocb == NULL || buf == NULL) {
       if (ocb != NULL) {
       if (ocb != NULL) {