New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(EC)DSA signature fix #670

Merged
merged 4 commits into from Jul 20, 2017

Conversation

Projects
None yet
4 participants
@reaperhulk
Member

reaperhulk commented Jul 20, 2017

Supersedes #668

jzakrzew and others added some commits Jul 19, 2017

Ask for signature length before allocating a buffer.
This fixes a potential heap buffer overflow that may happen when a signature
is longer than the private key, as with X9.62 ECDSA (#609).

@reaperhulk reaperhulk force-pushed the reaperhulk:jza-master branch from ab968c7 to 0be1eee Jul 20, 2017

@codecov

This comment has been minimized.

codecov bot commented Jul 20, 2017

Codecov Report

Merging #670 into master will increase coverage by <.01%.
The diff coverage is 100%.

Impacted file tree graph

@@            Coverage Diff             @@
##           master     #670      +/-   ##
==========================================
+ Coverage   96.94%   96.95%   +<.01%     
==========================================
  Files          18       18              
  Lines        5737     5746       +9     
  Branches      401      401              
==========================================
+ Hits         5562     5571       +9     
  Misses        117      117              
  Partials       58       58
Impacted Files Coverage Δ
tests/test_crypto.py 98.62% <100%> (ø) ⬆️
src/OpenSSL/crypto.py 96.8% <100%> (ø) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 8102128...e9b6f82. Read the comment docs.

@hynek

hynek approved these changes Jul 20, 2017

@hynek hynek merged commit 59d2625 into pyca:master Jul 20, 2017

3 checks passed

codecov/patch 100% of diff hit (target 96.94%)
Details
codecov/project 96.95% (+<.01%) compared to 8102128
Details
continuous-integration/travis-ci/pr The Travis CI build passed
Details

@hynek hynek deleted the reaperhulk:jza-master branch Jul 20, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment