Fix mock_crypto_pk_public_checksig__nocheck() to handle short RSA keys

This function -- a mock replacement used only for fuzzing -- would
have a buffer overflow if it got an RSA key whose modulus was under
20 bytes long.

Fortunately, Tor itself does not appear to have a bug here.

Fixes bug 24247; bugfix on 0.3.0.3-alpha when fuzzing was
introduced.  Found by OSS-Fuzz; this is OSS-Fuzz issue 4177.
This commit is contained in:
Nick Mathewson
2017-11-11 14:42:39 -05:00
parent 512dfa15ed
commit a7ca71cf6b
2 changed files with 9 additions and 2 deletions
+3 -2
View File
@@ -28,8 +28,9 @@ mock_crypto_pk_public_checksig__nocheck(const crypto_pk_t *env, char *to,
(void)fromlen;
/* We could look at from[0..fromlen-1] ... */
tor_assert(tolen >= crypto_pk_keysize(env));
memset(to, 0x01, 20);
return 20;
size_t siglen = MIN(20, crypto_pk_keysize(env));
memset(to, 0x01, siglen);
return (int)siglen;
}
static int