krb5 commit: Fix k5crypto NSS iov processing bug

Greg Hudson ghudson at mit.edu
Wed Dec 9 19:32:30 EST 2015


https://github.com/krb5/krb5/commit/08fafff29a11e61036021196aaae8c303d1a5662
commit 08fafff29a11e61036021196aaae8c303d1a5662
Author: Greg Hudson <ghudson at mit.edu>
Date:   Mon Dec 7 12:16:41 2015 -0500

    Fix k5crypto NSS iov processing bug
    
    In k5_nss_gen_stream_iov(), don't stop processing the iov array if we
    run across a zero-length iov.
    
    ticket: 8300 (new)
    target_version: 1.14-next
    tags: pullup

 src/lib/crypto/nss/enc_provider/enc_gen.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/src/lib/crypto/nss/enc_provider/enc_gen.c b/src/lib/crypto/nss/enc_provider/enc_gen.c
index 7022a78..cfe0d65 100644
--- a/src/lib/crypto/nss/enc_provider/enc_gen.c
+++ b/src/lib/crypto/nss/enc_provider/enc_gen.c
@@ -307,7 +307,7 @@ k5_nss_gen_stream_iov(krb5_key krb_key, krb5_data *state,
         int return_length;
         iov = &data[i];
         if (iov->data.length <= 0)
-            break;
+            continue;
 
         if (ENCRYPT_IOV(iov)) {
             rv = PK11_CipherOp(ctx, (unsigned char *)iov->data.data,


More information about the cvs-krb5 mailing list