checking mpz_export return value properly

fixes a potential DoS attack if a DH value of zero gets processed
This commit is contained in:
Martin Willi
2008-09-17 08:10:48 +00:00
parent b33c11b6c7
commit 73f6886a50
4 changed files with 32 additions and 8 deletions
@@ -191,6 +191,10 @@ static chunk_t rsadp(private_gmp_rsa_private_key_t *this, chunk_t data)
decrypted.len = this->k;
decrypted.ptr = mpz_export(NULL, NULL, 1, decrypted.len, 1, 0, t1);
if (decrypted.ptr == NULL)
{
decrypted.len = 0;
}
mpz_clear_randomized(t1);
mpz_clear_randomized(t2);