krb5 commit [krb5-1.14]: Fix k5crypto NSS iov processing bug

Tom Yu tlyu at mit.edu
Thu Dec 17 15:44:18 EST 2015


https://github.com/krb5/krb5/commit/4682cfb7696231ddf4a34f9d048233012266b657
commit 4682cfb7696231ddf4a34f9d048233012266b657
Author: Greg Hudson <ghudson at mit.edu>
Date:   Mon Dec 7 12:16:41 2015 -0500

    Fix k5crypto NSS iov processing bug
    
    In k5_nss_gen_stream_iov(), don't stop processing the iov array if we
    run across a zero-length iov.
    
    (cherry picked from commit 08fafff29a11e61036021196aaae8c303d1a5662)
    
    ticket: 8300
    version_fixed: 1.14.1

 src/lib/crypto/nss/enc_provider/enc_gen.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/src/lib/crypto/nss/enc_provider/enc_gen.c b/src/lib/crypto/nss/enc_provider/enc_gen.c
index 7022a78..cfe0d65 100644
--- a/src/lib/crypto/nss/enc_provider/enc_gen.c
+++ b/src/lib/crypto/nss/enc_provider/enc_gen.c
@@ -307,7 +307,7 @@ k5_nss_gen_stream_iov(krb5_key krb_key, krb5_data *state,
         int return_length;
         iov = &data[i];
         if (iov->data.length <= 0)
-            break;
+            continue;
 
         if (ENCRYPT_IOV(iov)) {
             rv = PK11_CipherOp(ctx, (unsigned char *)iov->data.data,


More information about the cvs-krb5 mailing list