summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDoug Hogan <doug@cvs.openbsd.org>2015-04-29 01:39:33 +0000
committerDoug Hogan <doug@cvs.openbsd.org>2015-04-29 01:39:33 +0000
commitd4083db7ddbe3c4734c569c4cac2a9445c81e7ed (patch)
treed6d8c87142897ebfd7d8ba3834d9f475b998b77a
parent1a96ac813b27bd488eeea5da2b39538f1c0c6632 (diff)
Added len_len error checking for internal cbb_buffer_add_u().
ok jsing@
-rw-r--r--lib/libssl/src/ssl/bs_cbb.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/lib/libssl/src/ssl/bs_cbb.c b/lib/libssl/src/ssl/bs_cbb.c
index 5546fac97f0..7f0e474dede 100644
--- a/lib/libssl/src/ssl/bs_cbb.c
+++ b/lib/libssl/src/ssl/bs_cbb.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: bs_cbb.c,v 1.5 2015/02/07 06:10:32 doug Exp $ */
+/* $OpenBSD: bs_cbb.c,v 1.6 2015/04/29 01:39:32 doug Exp $ */
/*
* Copyright (c) 2014, Google Inc.
*
@@ -127,6 +127,9 @@ cbb_buffer_add_u(struct cbb_buffer_st *base, uint32_t v, size_t len_len)
if (len_len == 0)
return 1;
+ if (len_len > 4)
+ return 0;
+
if (!cbb_buffer_add(base, &buf, len_len))
return 0;