Uploaded image for project: 'Santuario'
  1. Santuario
  2. SANTUARIO-491

Default KeyInfo resolver doesn't check for empty element content.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • C++ 1.5.1, C++ 1.6.0, C++ 1.6.1, C++ 1.7.0, C++ 1.7.1, C++ 1.7.2, C++ 1.7.3, C++ 2.0.0
    • C++ 2.0.1
    • C++
    • None

    Description

      The KeyInfo cases for RSA/DSA/EC/DER don't have null guards around the extraction of the fields into safeBuffers, leading to crashes.

      Attachments

        Activity

          People

            scantor Scott Cantor
            scantor Scott Cantor
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: