mirror of
https://github.com/curl/curl.git
synced 2026-07-24 18:57:18 +03:00
x509asn1: fix heap over-read when parsing x509 certificates
Assisted-by: Patrick Monnerat Closes #7536
This commit is contained in:
parent
881a8c4e10
commit
5f3ca7f773
1 changed files with 10 additions and 9 deletions
|
|
@ -34,6 +34,7 @@
|
|||
#include "inet_pton.h"
|
||||
#include "curl_base64.h"
|
||||
#include "x509asn1.h"
|
||||
#include "dynbuf.h"
|
||||
|
||||
/* The last 3 #include files should be in this order */
|
||||
#include "curl_printf.h"
|
||||
|
|
@ -205,16 +206,16 @@ static const char *bool2str(const char *beg, const char *end)
|
|||
*/
|
||||
static const char *octet2str(const char *beg, const char *end)
|
||||
{
|
||||
size_t n = end - beg;
|
||||
char *buf = NULL;
|
||||
struct dynbuf buf;
|
||||
CURLcode result;
|
||||
|
||||
if(n <= (SIZE_T_MAX - 1) / 3) {
|
||||
buf = malloc(3 * n + 1);
|
||||
if(buf)
|
||||
for(n = 0; beg < end; n += 3)
|
||||
msnprintf(buf + n, 4, "%02x:", *(const unsigned char *) beg++);
|
||||
}
|
||||
return buf;
|
||||
Curl_dyn_init(&buf, 3 * CURL_ASN1_MAX + 1);
|
||||
result = Curl_dyn_addn(&buf, "", 0);
|
||||
|
||||
while(!result && beg < end)
|
||||
result = Curl_dyn_addf(&buf, "%02x:", (unsigned char) *beg++);
|
||||
|
||||
return Curl_dyn_ptr(&buf);
|
||||
}
|
||||
|
||||
static const char *bit2str(const char *beg, const char *end)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue