X-Git-Url: https://git.distorted.org.uk/~mdw/secnet/blobdiff_plain/076bb54e68477f883033bee696c9c5f801ece2f2..94c61b9cd7bf02f4cebfe0fb580db61e6e8bf636:/transform.c diff --git a/transform.c b/transform.c index 8fdf9fd..f55aa44 100644 --- a/transform.c +++ b/transform.c @@ -171,6 +171,10 @@ static uint32_t transform_reverse(void *sst, struct buffer_if *buf, return 1; } + if (buf->size < 4 + 16 + 16) { + *errmsg="msg too short"; + return 1; + } /* CBC */ memset(iv,0,16); @@ -181,6 +185,7 @@ static uint32_t transform_reverse(void *sst, struct buffer_if *buf, /* Assert bufsize is multiple of blocksize */ if (buf->size&0xf) { *errmsg="msg not multiple of cipher blocksize"; + return 1; } serpent_encrypt(&ti->cryptkey,iv,iv); for (n=buf->start; nstart+buf->size; n+=16)