From c0bf721357050a65141146d494f7a09e3ed3962e Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Wed, 15 Oct 2014 14:17:30 +0200 Subject: tls: Check all bytes of the padding if they equal the padding length --- src/libtls/tls_aead_impl.c | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'src/libtls/tls_aead_impl.c') diff --git a/src/libtls/tls_aead_impl.c b/src/libtls/tls_aead_impl.c index fb14026e0..d529ceba7 100644 --- a/src/libtls/tls_aead_impl.c +++ b/src/libtls/tls_aead_impl.c @@ -100,6 +100,7 @@ METHOD(tls_aead_t, decrypt, bool, chunk_t assoc, mac, iv; u_int8_t bs, padlen; sigheader_t hdr; + size_t i; bs = this->crypter->get_block_size(this->crypter); if (data->len < bs || data->len < this->iv.len || data->len % bs) @@ -116,6 +117,13 @@ METHOD(tls_aead_t, decrypt, bool, padlen = data->ptr[data->len - 1]; if (padlen < data->len) { /* If padding looks valid, remove it */ + for (i = data->len - padlen - 1; i < data->len - 1; i++) + { + if (data->ptr[i] != padlen) + { + return FALSE; + } + } data->len -= padlen + 1; } -- cgit v1.2.3