Skip to content
  1. Apr 25, 2018
    • Nicola Tuveri's avatar
      [SM2_sign] fix double free and return value · 67cc2bae
      Nicola Tuveri authored
      
      
      Currently, critical bugs prevent using SM2 signatures through the
      `EVP_PKEY` interface: any application that managed to satisfy the
      requirement of forcing SM3 as the message digest – even if this is
      currently not possible transparently through the `EVP_PKEY` interface
      and requires manually forcing the MD selection – would crash with a
      segmentation fault upon calling the `SM2_sign()` function.
      
      This is easily verified using the OpenSSL CLI to execute this critical
      code path under the right conditions:
      `openssl dgst -sm3 -hex -sign sm2.eckey /path/to/file/to/sign`
      
      The issue is caused by a double free at the end of `SM2_sign()` in
      `crypto/sm2/sm2_sign.c` in case of successful signature generation.
      In addition, even if the double free was not causing segfaults,
      the function returns the wrong return value in case of success (it
      would return 0 rather than 1).
      
      This patch fixes both problems.
      
      Reviewed-by: default avatarBernd Edlinger <bernd.edlinger@hotmail.de>
      Reviewed-by: default avatarMatt Caswell <matt@openssl.org>
      (Merged from https://github.com/openssl/openssl/pull/6066)
      67cc2bae
    • Matt Caswell's avatar
      Fix the MAX_CURVELIST definition · ca50cd91
      Matt Caswell authored
      
      
      The MAX_CURVELIST macro defines the total number of in-built SSL/TLS curves
      that we support. However it has not been updated as new curves are added.
      
      Fixes #5232
      
      Reviewed-by: default avatarBernd Edlinger <bernd.edlinger@hotmail.de>
      (Merged from https://github.com/openssl/openssl/pull/6065)
      ca50cd91
  2. Apr 24, 2018
  3. Apr 23, 2018
  4. Apr 22, 2018
  5. Apr 20, 2018