lib: accept larger input to md5/hmac/sha256/sha512 functions

Avoid unchecked data conversions from size_t to unsigned int.

Reported-by: James Fuller
Closes #21174
This commit is contained in:
Daniel Stenberg 2026-03-31 11:22:34 +02:00
parent 1570091f10
commit dd7fcd581f
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
7 changed files with 41 additions and 20 deletions

View file

@ -540,14 +540,19 @@ const struct MD5_params Curl_DIGEST_MD5 = {
* Returns CURLE_OK on success.
*/
CURLcode Curl_md5it(unsigned char *output,
const unsigned char *input, const size_t len)
const unsigned char *input, size_t len)
{
CURLcode result;
my_md5_ctx ctx;
result = my_md5_init(&ctx);
if(!result) {
my_md5_update(&ctx, input, curlx_uztoui(len));
do {
unsigned int ilen = (unsigned int) CURLMIN(len, UINT_MAX);
my_md5_update(&ctx, input, ilen);
input += ilen;
len -= len;
} while(len);
my_md5_final(output, &ctx);
}
return result;