Re: [PATCH gnupg] common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp.

Werner Koch via Gnupg-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
On Fri, 23 May 2025 23:52, Collin Funk said:

> -  else if (toklen == 10 || !memcmp ("public-key", tok, toklen))
> +  else if (toklen == 10 && !memcmp ("public-key", tok, toklen))

Uiih, a classic brown paper bag bug for me.  Fortunately the code is
only used by PKCS#15 cards as an early check for a proper public key.

Thanks.  Will be applied soon.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
openpgp-digital-signature.asc (application/pgp-signature, 247 B)
-----BEGIN PGP SIGNATURE-----

iIMEARYKACsWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCaDGseQ0cd2tAZ251cGcu
b3JnAAoJEBnMHJ4IWxB6r4kA/A4dUpzd+PFTEIIg4BUiuC3xkgwYbgpJWWhMCAw1
yTcGAQDyC0MoADuidgq8brOgPrDVtyyuueuWcG5rmubcUIn8AA==
=PBJu
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.