From 0b989c7b20be8e575eda66bf1e107b38b187e08b Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Thu, 31 Aug 2023 14:27:09 +0200 Subject: [PATCH] botan: Reject EC keys with explicitly encoded parameters This requires a function that will be added in the upcoming Botan 3.2 release. --- configure.ac | 2 +- src/libstrongswan/plugins/botan/botan_ec_public_key.c | 8 ++++++++ 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac index e89e702be..365f5cb96 100644 --- a/configure.ac +++ b/configure.ac @@ -1215,7 +1215,7 @@ if test x$botan = xtrue; then AC_SUBST(botan_LIBS) saved_LIBS=$LIBS LIBS="$botan_LIBS" - AC_CHECK_FUNCS(botan_rng_init_custom) + AC_CHECK_FUNCS(botan_rng_init_custom botan_pubkey_ecc_key_used_explicit_encoding) LIBS=$saved_LIBS fi diff --git a/src/libstrongswan/plugins/botan/botan_ec_public_key.c b/src/libstrongswan/plugins/botan/botan_ec_public_key.c index 95def4fa7..bd23bd0c8 100644 --- a/src/libstrongswan/plugins/botan/botan_ec_public_key.c +++ b/src/libstrongswan/plugins/botan/botan_ec_public_key.c @@ -235,6 +235,14 @@ botan_ec_public_key_t *botan_ec_public_key_adopt(botan_pubkey_t key) { private_botan_ec_public_key_t *this; +#ifdef HAVE_BOTAN_PUBKEY_ECC_KEY_USED_EXPLICIT_ENCODING + if (botan_pubkey_ecc_key_used_explicit_encoding(key)) + { + botan_pubkey_destroy(key); + return NULL; + } +#endif + INIT(this, .public = { .key = {