crypto: Define MODP_CUSTOM outside of IKE DH range

Before this fix it was possible to crash charon with an IKE_SA_INIT
message containing a KE payload with DH group MODP_CUSTOM(1025).
Defining MODP_CUSTOM outside of the two byte IKE DH identifier range
prevents it from getting negotiated.

Fixes CVE-2014-9221.
This commit is contained in:
Tobias Brunner
2014-12-23 15:40:01 +01:00
committed by Andreas Steffen
parent 6683cf6a5a
commit e13ef5c434
9 changed files with 17 additions and 14 deletions
+1 -1
View File
@@ -56,7 +56,7 @@ struct private_ntru_ke_t {
/**
* Diffie Hellman group number.
*/
u_int16_t group;
diffie_hellman_group_t group;
/**
* NTRU Parameter Set