mirror of https://github.com/wolfSSL/wolfssl.git
add sanity check on padSz
parent
a77085960e
commit
85437e4097
|
@ -15335,6 +15335,13 @@ int ProcessReply(WOLFSSL* ssl)
|
||||||
if (ssl->options.tls1_3) {
|
if (ssl->options.tls1_3) {
|
||||||
word16 i = (word16)(ssl->buffers.inputBuffer.length -
|
word16 i = (word16)(ssl->buffers.inputBuffer.length -
|
||||||
ssl->keys.padSz);
|
ssl->keys.padSz);
|
||||||
|
|
||||||
|
/* sanity check on underflow */
|
||||||
|
if (ssl->keys.padSz >= ssl->buffers.inputBuffer.length) {
|
||||||
|
WOLFSSL_ERROR(DECRYPT_ERROR);
|
||||||
|
return DECRYPT_ERROR;
|
||||||
|
}
|
||||||
|
|
||||||
/* Remove padding from end of plain text. */
|
/* Remove padding from end of plain text. */
|
||||||
for (--i; i > ssl->buffers.inputBuffer.idx; i--) {
|
for (--i; i > ssl->buffers.inputBuffer.idx; i--) {
|
||||||
if (ssl->buffers.inputBuffer.buffer[i] != 0)
|
if (ssl->buffers.inputBuffer.buffer[i] != 0)
|
||||||
|
|
Loading…
Reference in New Issue