]> git.ipfire.org Git - thirdparty/gnutls.git/commitdiff
Fix off-by-one size computation that leads to truncated strings.
authorSimon Josefsson <simon@josefsson.org>
Mon, 22 Jun 2009 09:30:05 +0000 (11:30 +0200)
committerSimon Josefsson <simon@josefsson.org>
Mon, 22 Jun 2009 09:30:05 +0000 (11:30 +0200)
Reported by Tim Kosse <tim.kosse@filezilla-project.org> in
<http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3651>.

lib/x509/dn.c

index 662fd9f23682cfa5945607b63b699a7e912dab2b..daf14dfece5c8fc369020f731e9ab080373129e5 100644 (file)
@@ -36,7 +36,7 @@
  */
 
 /* Converts the given OID to an ldap acceptable string or
- * a dotted OID. 
+ * a dotted OID.
  */
 static const char *
 oid2ldap_string (const char *oid)
@@ -240,7 +240,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
          ldap_desc = oid2ldap_string (oid);
          printable = _gnutls_x509_oid_data_printable (oid);
 
-         sizeof_escaped = 2 * len + 1;
+         /* leading #, hex encoded value and terminating NULL */
+         sizeof_escaped = 2 * len + 2;
 
          escaped = gnutls_malloc (sizeof_escaped);
          if (escaped == NULL)
@@ -310,7 +311,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
       _gnutls_string_get_data( &out_str, buf, sizeof_buf);
       buf[*sizeof_buf] = 0;
     }
-  else 
+  else
     *sizeof_buf = out_str.length;
 
   result = 0;