openssl/crypto/asn1
Emilia Kasper 57b0c4697a Fix OID handling:
- Upon parsing, reject OIDs with invalid base-128 encoding.
- Always NUL-terminate the destination buffer in OBJ_obj2txt printing function.

CVE-2014-3508

Reviewed-by: Dr. Stephen Henson <steve@openssl.org>
Reviewed-by: Kurt Roeckx <kurt@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
2014-08-06 21:30:39 +01:00
..
.cvsignore Add emacs cache files to .cvsignore. 2005-04-11 14:17:07 +00:00
a_bitstr.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
a_bool.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
a_bytes.c PR: 1835 2009-02-14 21:49:38 +00:00
a_d2i_fp.c Check for potentially exploitable overflows in asn1_d2i_read_bio 2012-04-19 11:44:51 +00:00
a_digest.c Consistency. 2005-03-31 13:57:54 +00:00
a_dup.c PR: 1644 2009-09-06 15:49:12 +00:00
a_enum.c - use BN_set_negative and BN_is_negative instead of BN_set_sign 2005-04-22 20:02:44 +00:00
a_gentm.c Fix error codes. 2009-04-05 11:54:34 +00:00
a_i2d_fp.c Update util/ck_errf.pl script, and have it run automatically 2005-05-09 00:27:37 +00:00
a_int.c Encode INTEGER correctly. 2013-03-18 14:21:03 +00:00
a_mbstr.c Fix unitialized warnings 2009-10-04 16:52:35 +00:00
a_object.c Fix OID handling: 2014-08-06 21:30:39 +01:00
a_octet.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
a_print.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
a_set.c PR: 1996 2009-07-27 21:21:25 +00:00
a_sign.c Add support for default public key digest type ctrl. 2006-05-07 17:09:39 +00:00
a_strex.c Fix Valgrind warning. 2012-09-24 19:50:00 +00:00
a_strnid.c Set default global mask to UTF8 only. 2014-06-01 15:04:35 +01:00
a_time.c PR: 1985 2009-07-11 21:42:47 +00:00
a_type.c Fix some warnings. 2008-03-16 20:59:10 +00:00
a_utctm.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
a_utf8.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
a_verify.c Don't try and verify signatures if key is NULL (CVE-2013-0166) 2013-02-05 16:46:15 +00:00
ameth_lib.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
asn1.h PR: 2433 2011-01-24 16:20:15 +00:00
asn1_err.c Fix various spelling errors 2014-02-14 22:36:04 +00:00
asn1_gen.c PR: 2090 2009-11-10 00:47:37 +00:00
asn1_lib.c ASN1 sanity check. 2014-07-02 01:01:41 +01:00
asn1_locl.h Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
asn1_mac.h Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
asn1_par.c PR: 2056 2009-10-01 00:11:49 +00:00
asn1t.h Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
asn_mime.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
asn_moid.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
asn_pack.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
bio_asn1.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
bio_ndef.c no need to include memory.h 2011-04-30 23:38:24 +00:00
charmap.h Bunch of constifications. 2007-10-13 15:51:32 +00:00
charmap.pl Add license info. 2014-07-04 18:44:24 +01:00
d2i_pr.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
d2i_pu.c PR: 2088 2009-11-12 19:57:39 +00:00
evp_asn1.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
f_enum.c There have been a number of complaints from a number of sources that names 2000-06-01 22:19:21 +00:00
f_int.c Security fixes brought forward from 0.9.7. 2002-11-13 15:43:43 +00:00
f_string.c There have been a number of complaints from a number of sources that names 2000-06-01 22:19:21 +00:00
i2d_pr.c Submitted by: "Victor B. Wagner" <vitus@cryptocom.ru> 2007-11-20 13:37:51 +00:00
i2d_pu.c ecc api cleanup; summary: 2005-05-16 10:11:04 +00:00
Makefile Update dependencies. 2008-03-22 18:52:03 +00:00
n_pkey.c Fix warnings (From HEAD, original patch by Ben). 2010-06-15 17:25:15 +00:00
nsseq.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
p5_pbe.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
p5_pbev2.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
p8_pkey.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
t_bitst.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
t_crl.c Fix warnings (From HEAD, original patch by Ben). 2010-06-15 17:25:15 +00:00
t_pkey.c Revert to original... 2006-04-15 13:15:25 +00:00
t_req.c Fix X509_REQ_print_ex() to process extension options. 2007-05-22 23:31:29 +00:00
t_spki.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
t_x509.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
t_x509a.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
tasn_dec.c Fix warnings (From HEAD, original patch by Ben). 2010-06-15 17:25:15 +00:00
tasn_enc.c Memory leak and NULL dereference fixes. 2014-06-27 14:53:21 +01:00
tasn_fre.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
tasn_new.c PR: 2013 2009-09-02 13:55:22 +00:00
tasn_prn.c ans1/tasn_prn.c: avoid bool in variable names [from HEAD]. 2012-03-29 17:51:37 +00:00
tasn_typ.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
tasn_utl.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_algor.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_attrib.c More linker bloat reorganisation: 2001-07-27 02:22:42 +00:00
x_bignum.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_crl.c Tolerate critical AKID in CRLs. 2014-06-27 18:50:45 +01:00
x_exten.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_info.c Merge from the ASN1 branch of new ASN1 code 2000-12-08 19:09:35 +00:00
x_long.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_name.c PR: 2736 2012-02-27 18:45:06 +00:00
x_nx509.c Update obsolete email address... 2008-11-05 18:39:08 +00:00
x_pkey.c Revert the size_t modifications from HEAD that had led to more 2008-11-12 03:58:08 +00:00
x_pubkey.c PR: 2813 2012-05-11 13:50:09 +00:00
x_req.c Using correct lock for X509_REQ. 2006-09-22 17:06:09 +00:00
x_sig.c Get rid of ASN1_ITEM_FUNCTIONS dummy function 2001-02-23 12:47:06 +00:00
x_spki.c Get rid of ASN1_ITEM_FUNCTIONS dummy function 2001-02-23 12:47:06 +00:00
x_val.c Get rid of ASN1_ITEM_FUNCTIONS dummy function 2001-02-23 12:47:06 +00:00
x_x509.c Add call to ENGINE_register_all_complete() to ENGINE_load_builtin_engines(), 2010-10-03 18:57:01 +00:00
x_x509a.c Update obsolete email address... 2008-11-05 18:39:08 +00:00