From 61c738ebca2135252279932c8b1dfb301636d20f Mon Sep 17 00:00:00 2001 From: Nikos Mavrogiannopoulos Date: Sun, 6 Aug 2017 11:34:39 +0200 Subject: wrap_nettle_pk_fixup: added sanity check in RSA-PSS param checking Signed-off-by: Nikos Mavrogiannopoulos --- lib/nettle/pk.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/nettle/pk.c b/lib/nettle/pk.c index cd7dce243b..68260e4071 100644 --- a/lib/nettle/pk.c +++ b/lib/nettle/pk.c @@ -2298,7 +2298,7 @@ wrap_nettle_pk_fixup(gnutls_pk_algorithm_t algo, * keys were as old. */ if (params->params_nr < RSA_PRIVATE_PARAMS - 3) - return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST); + return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY); if (params->params[RSA_COEF] == NULL) { ret = _gnutls_mpi_init(¶ms->params[RSA_COEF]); @@ -2347,6 +2347,9 @@ wrap_nettle_pk_fixup(gnutls_pk_algorithm_t algo, ed25519_sha512_public_key(params->raw_pub.data, params->raw_priv.data); params->raw_pub.size = params->raw_priv.size; } else if (algo == GNUTLS_PK_RSA_PSS) { + if (params->params_nr < RSA_PRIVATE_PARAMS - 3) + return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY); + if (params->spki.rsa_pss_dig != 0) { unsigned pub_size = nettle_mpz_sizeinbase_256_u(TOMPZ(params->params[RSA_MODULUS])); /* sanity check for private key */ -- cgit v1.2.1