~mdw
/
sgt
/
putty
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
| inline |
side by side
Add another missing bounds check in the SSH-1 private key loader.
[sgt/putty]
/
sshpubk.c
diff --git
a/sshpubk.c
b/sshpubk.c
index
bd3c5e4
..
b860040
100644
(file)
--- a/
sshpubk.c
+++ b/
sshpubk.c
@@
-74,7
+74,7
@@
static int loadrsakey_main(FILE * fp, struct RSAKey *key, int pub_only,
/* Next, the comment field. */
j = GET_32BIT(buf + i);
i += 4;
- if (len - i < j)
+ if (
j < 0 ||
len - i < j)
goto end;
comment = snewn(j + 1, char);
if (comment) {