Skip to content

Commit

Permalink
cyassl: Check for invalid length parameter in Curl_cyassl_random
Browse files Browse the repository at this point in the history
  • Loading branch information
jay authored and bagder committed Mar 25, 2015
1 parent ec31962 commit d29f8b4
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion lib/vtls/cyassl.c
Expand Up @@ -640,7 +640,9 @@ int Curl_cyassl_random(struct SessionHandle *data,
(void)data;
if(InitRng(&rng))
return 1;
if(RNG_GenerateBlock(&rng, entropy, length))
if(length > UINT_MAX)
return 1;
if(RNG_GenerateBlock(&rng, entropy, (unsigned)length))
return 1;
return 0;
}
Expand Down

0 comments on commit d29f8b4

Please sign in to comment.