X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ian/git?a=blobdiff_plain;f=transform.c;h=f1da5642099d0d1ec7f1546498985e60b06a5157;hb=07e4774c32915eeb1d480854a4a10ec91160b57d;hp=8fdf9fd80a350b254bb4e2d7380a31a9babc77f9;hpb=076bb54e68477f883033bee696c9c5f801ece2f2;p=secnet.git diff --git a/transform.c b/transform.c index 8fdf9fd..f1da564 100644 --- a/transform.c +++ b/transform.c @@ -171,6 +171,10 @@ static uint32_t transform_reverse(void *sst, struct buffer_if *buf, return 1; } + if (buf->size < 4 + 16 + 16) { + *errmsg="msg too short"; + return 1; + } /* CBC */ memset(iv,0,16); @@ -181,6 +185,7 @@ static uint32_t transform_reverse(void *sst, struct buffer_if *buf, /* Assert bufsize is multiple of blocksize */ if (buf->size&0xf) { *errmsg="msg not multiple of cipher blocksize"; + return 1; } serpent_encrypt(&ti->cryptkey,iv,iv); for (n=buf->start; nstart+buf->size; n+=16) @@ -242,7 +247,7 @@ static uint32_t transform_reverse(void *sst, struct buffer_if *buf, } else { /* Too much skew */ *errmsg="seqnum: too much skew"; - return 1; + return 2; } return 0;