Check rng return value when generating DH secrets and primes in gmp plugin

This commit is contained in:
Tobias Brunner
2012-07-16 14:53:35 +02:00
committed by Martin Willi
parent e93bb353d5
commit 5025135f70
3 changed files with 19 additions and 13 deletions
@@ -230,8 +230,13 @@ static gmp_diffie_hellman_t *create_generic(diffie_hellman_group_t group,
destroy(this); destroy(this);
return NULL; return NULL;
} }
if (!rng->allocate_bytes(rng, exp_len, &random))
rng->allocate_bytes(rng, exp_len, &random); {
DBG1(DBG_LIB, "failed to allocate DH secret");
rng->destroy(rng);
destroy(this);
return NULL;
}
rng->destroy(rng); rng->destroy(rng);
if (exp_len == this->p_len) if (exp_len == this->p_len)
@@ -149,7 +149,12 @@ static status_t compute_prime(private_gmp_rsa_private_key_t *this,
mpz_init(*prime); mpz_init(*prime);
do do
{ {
rng->allocate_bytes(rng, prime_size, &random_bytes); if (!rng->allocate_bytes(rng, prime_size, &random_bytes))
{
DBG1(DBG_LIB, "failed to allocate random prime");
rng->destroy(rng);
return FAILED;
}
/* make sure the two most significant bits are set */ /* make sure the two most significant bits are set */
random_bytes.ptr[0] = random_bytes.ptr[0] | 0xC0; random_bytes.ptr[0] = random_bytes.ptr[0] | 0xC0;
@@ -314,7 +314,7 @@ METHOD(public_key_t, encrypt_, bool,
{ {
chunk_t em; chunk_t em;
u_char *pos; u_char *pos;
int padding, i; int padding;
rng_t *rng; rng_t *rng;
if (scheme != ENCRYPT_RSA_PKCS1) if (scheme != ENCRYPT_RSA_PKCS1)
@@ -348,16 +348,12 @@ METHOD(public_key_t, encrypt_, bool,
*pos++ = 0x02; *pos++ = 0x02;
/* fill with pseudo random octets */ /* fill with pseudo random octets */
rng->get_bytes(rng, padding, pos); if (!rng_get_bytes_not_zero(rng, padding, pos, TRUE))
/* replace zero-valued random octets */
for (i = 0; i < padding; i++)
{ {
while (*pos == 0) DBG1(DBG_LIB, "failed to allocate padding");
{ chunk_clear(&em);
rng->get_bytes(rng, 1, pos); rng->destroy(rng);
} return FALSE;
pos++;
} }
rng->destroy(rng); rng->destroy(rng);