@@ -261,6 +261,28 @@ PKCS7_dataInit(PKCS7 *p7, BIO *bio)
261261 PKCS7_RECIP_INFO * ri = NULL ;
262262 ASN1_OCTET_STRING * os = NULL ;
263263
264+ if (p7 == NULL ) {
265+ PKCS7err (PKCS7_F_PKCS7_DATAINIT , PKCS7_R_INVALID_NULL_POINTER );
266+ return NULL ;
267+ }
268+
269+ /*
270+ * The content field in the PKCS7 ContentInfo is optional,
271+ * but that really only applies to inner content (precisely,
272+ * detached signatures).
273+ *
274+ * When reading content, missing outer content is therefore
275+ * treated as an error.
276+ *
277+ * When creating content, PKCS7_content_new() must be called
278+ * before calling this method, so a NULL p7->d is always
279+ * an error.
280+ */
281+ if (p7 -> d .ptr == NULL ) {
282+ PKCS7err (PKCS7_F_PKCS7_DATAINIT , PKCS7_R_NO_CONTENT );
283+ return NULL ;
284+ }
285+
264286 i = OBJ_obj2nid (p7 -> type );
265287 p7 -> state = PKCS7_S_HEADER ;
266288
@@ -417,6 +439,17 @@ PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
417439 unsigned char * ek = NULL , * tkey = NULL ;
418440 int eklen = 0 , tkeylen = 0 ;
419441
442+ if (p7 == NULL ) {
443+ PKCS7err (PKCS7_F_PKCS7_DATADECODE ,
444+ PKCS7_R_INVALID_NULL_POINTER );
445+ return NULL ;
446+ }
447+
448+ if (p7 -> d .ptr == NULL ) {
449+ PKCS7err (PKCS7_F_PKCS7_DATADECODE , PKCS7_R_NO_CONTENT );
450+ return NULL ;
451+ }
452+
420453 i = OBJ_obj2nid (p7 -> type );
421454 p7 -> state = PKCS7_S_HEADER ;
422455
@@ -691,6 +724,17 @@ PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
691724 STACK_OF (PKCS7_SIGNER_INFO ) * si_sk = NULL ;
692725 ASN1_OCTET_STRING * os = NULL ;
693726
727+ if (p7 == NULL ) {
728+ PKCS7err (PKCS7_F_PKCS7_DATAFINAL ,
729+ PKCS7_R_INVALID_NULL_POINTER );
730+ return 0 ;
731+ }
732+
733+ if (p7 -> d .ptr == NULL ) {
734+ PKCS7err (PKCS7_F_PKCS7_DATAFINAL , PKCS7_R_NO_CONTENT );
735+ return 0 ;
736+ }
737+
694738 EVP_MD_CTX_init (& ctx_tmp );
695739 i = OBJ_obj2nid (p7 -> type );
696740 p7 -> state = PKCS7_S_HEADER ;
@@ -736,6 +780,7 @@ PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
736780 /* If detached data then the content is excluded */
737781 if (PKCS7_type_is_data (p7 -> d .sign -> contents ) && p7 -> detached ) {
738782 M_ASN1_OCTET_STRING_free (os );
783+ os = NULL ;
739784 p7 -> d .sign -> contents -> d .data = NULL ;
740785 }
741786 break ;
@@ -750,6 +795,7 @@ PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
750795 if (PKCS7_type_is_data (p7 -> d .digest -> contents ) &&
751796 p7 -> detached ) {
752797 M_ASN1_OCTET_STRING_free (os );
798+ os = NULL ;
753799 p7 -> d .digest -> contents -> d .data = NULL ;
754800 }
755801 break ;
@@ -815,22 +861,32 @@ PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
815861 M_ASN1_OCTET_STRING_set (p7 -> d .digest -> digest , md_data , md_len );
816862 }
817863
818- if (!PKCS7_is_detached (p7 ) && !(os -> flags & ASN1_STRING_FLAG_NDEF )) {
819- char * cont ;
820- long contlen ;
821- btmp = BIO_find_type (bio , BIO_TYPE_MEM );
822- if (btmp == NULL ) {
823- PKCS7err (PKCS7_F_PKCS7_DATAFINAL ,
824- PKCS7_R_UNABLE_TO_FIND_MEM_BIO );
864+ if (!PKCS7_is_detached (p7 )) {
865+ /*
866+ * NOTE: only reach os == NULL here because detached
867+ * digested data support is broken?
868+ */
869+ if (os == NULL )
825870 goto err ;
871+ if (!(os -> flags & ASN1_STRING_FLAG_NDEF )) {
872+ char * cont ;
873+ long contlen ;
874+
875+ btmp = BIO_find_type (bio , BIO_TYPE_MEM );
876+ if (btmp == NULL ) {
877+ PKCS7err (PKCS7_F_PKCS7_DATAFINAL ,
878+ PKCS7_R_UNABLE_TO_FIND_MEM_BIO );
879+ goto err ;
880+ }
881+ contlen = BIO_get_mem_data (btmp , & cont );
882+ /*
883+ * Mark the BIO read only then we can use its copy
884+ * of the data instead of making an extra copy.
885+ */
886+ BIO_set_flags (btmp , BIO_FLAGS_MEM_RDONLY );
887+ BIO_set_mem_eof_return (btmp , 0 );
888+ ASN1_STRING_set0 (os , (unsigned char * )cont , contlen );
826889 }
827- contlen = BIO_get_mem_data (btmp , & cont );
828- /* Mark the BIO read only then we can use its copy of the data
829- * instead of making an extra copy.
830- */
831- BIO_set_flags (btmp , BIO_FLAGS_MEM_RDONLY );
832- BIO_set_mem_eof_return (btmp , 0 );
833- ASN1_STRING_set0 (os , (unsigned char * )cont , contlen );
834890 }
835891 ret = 1 ;
836892err :
@@ -905,6 +961,17 @@ PKCS7_dataVerify(X509_STORE *cert_store, X509_STORE_CTX *ctx, BIO *bio,
905961 STACK_OF (X509 ) * cert ;
906962 X509 * x509 ;
907963
964+ if (p7 == NULL ) {
965+ PKCS7err (PKCS7_F_PKCS7_DATAVERIFY ,
966+ PKCS7_R_INVALID_NULL_POINTER );
967+ return 0 ;
968+ }
969+
970+ if (p7 -> d .ptr == NULL ) {
971+ PKCS7err (PKCS7_F_PKCS7_DATAVERIFY , PKCS7_R_NO_CONTENT );
972+ return 0 ;
973+ }
974+
908975 if (PKCS7_type_is_signed (p7 )) {
909976 cert = p7 -> d .sign -> cert ;
910977 } else if (PKCS7_type_is_signedAndEnveloped (p7 )) {
@@ -941,6 +1008,7 @@ PKCS7_dataVerify(X509_STORE *cert_store, X509_STORE_CTX *ctx, BIO *bio,
9411008
9421009 return PKCS7_signatureVerify (bio , p7 , si , x509 );
9431010err :
1011+
9441012 return ret ;
9451013}
9461014
0 commit comments