summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNikos Mavrogiannopoulos <nmav@gnutls.org>2017-08-06 11:34:39 +0200
committerNikos Mavrogiannopoulos <nmav@gnutls.org>2017-08-06 11:35:34 +0200
commit61c738ebca2135252279932c8b1dfb301636d20f (patch)
treed497c96f83ba6658329eab37b8e68f8e94840d15
parent7bfa8ec3b09d6be960d0cb5ec7f6ca55c8fd88a0 (diff)
downloadgnutls-61c738ebca2135252279932c8b1dfb301636d20f.tar.gz
wrap_nettle_pk_fixup: added sanity check in RSA-PSS param checking
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
-rw-r--r--lib/nettle/pk.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/lib/nettle/pk.c b/lib/nettle/pk.c
index cd7dce243b..68260e4071 100644
--- a/lib/nettle/pk.c
+++ b/lib/nettle/pk.c
@@ -2298,7 +2298,7 @@ wrap_nettle_pk_fixup(gnutls_pk_algorithm_t algo,
* keys were as old.
*/
if (params->params_nr < RSA_PRIVATE_PARAMS - 3)
- return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
+ return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
if (params->params[RSA_COEF] == NULL) {
ret = _gnutls_mpi_init(&params->params[RSA_COEF]);
@@ -2347,6 +2347,9 @@ wrap_nettle_pk_fixup(gnutls_pk_algorithm_t algo,
ed25519_sha512_public_key(params->raw_pub.data, params->raw_priv.data);
params->raw_pub.size = params->raw_priv.size;
} else if (algo == GNUTLS_PK_RSA_PSS) {
+ if (params->params_nr < RSA_PRIVATE_PARAMS - 3)
+ return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
+
if (params->spki.rsa_pss_dig != 0) {
unsigned pub_size = nettle_mpz_sizeinbase_256_u(TOMPZ(params->params[RSA_MODULUS]));
/* sanity check for private key */