mirror of
https://github.com/openssl/openssl.git
synced 2025-02-05 14:10:53 +08:00
These calls invoke EVP_DigestInit() which can fail for digests with implicit fetches. Subsequent EVP_DigestUpdate() from BIO_write() or EVP_DigestFinal() from BIO_read() will segfault on NULL dereference. This can be triggered by an attacker providing PKCS7 data digested with MD4 for example if the legacy provider is not loaded. If BIO_set_md() fails the md BIO cannot be used. CVE-2023-0401 Reviewed-by: Paul Dale <pauli@openssl.org> Reviewed-by: Richard Levitte <levitte@openssl.org> |
||
---|---|---|
.. | ||
bio_pk7.c | ||
build.info | ||
pk7_asn1.c | ||
pk7_attr.c | ||
pk7_doit.c | ||
pk7_lib.c | ||
pk7_local.h | ||
pk7_mime.c | ||
pk7_smime.c | ||
pkcs7err.c |