2
0
Эх сурвалжийг харах

fix coverity finding: cbc_decrypt out-of-bound read

Karel Miko 8 жил өмнө
parent
commit
7246ab50da

+ 1 - 1
src/modes/cbc/cbc_decrypt.c

@@ -45,7 +45,7 @@ int cbc_decrypt(const unsigned char *ct, unsigned char *pt, unsigned long len, s
    }
    }
 
 
    /* is blocklen valid? */
    /* is blocklen valid? */
-   if (cbc->blocklen < 1 || cbc->blocklen > (int)sizeof(cbc->IV)) {
+   if (cbc->blocklen < 1 || cbc->blocklen > (int)sizeof(cbc->IV) || cbc->blocklen > (int)sizeof(tmp)) {
       return CRYPT_INVALID_ARG;
       return CRYPT_INVALID_ARG;
    }
    }