提交 7c517a04 编写于 作者: B Ben Laurie

Security fix.

上级 d78e5298
...@@ -12,6 +12,9 @@ ...@@ -12,6 +12,9 @@
*) applies to 0.9.6a/0.9.6b/0.9.6c and 0.9.7 *) applies to 0.9.6a/0.9.6b/0.9.6c and 0.9.7
+) applies to 0.9.7 only +) applies to 0.9.7 only
+) SECURITY: remove unsafe setjmp/signal interaction from ui_openssl.c.
[Ben Laurie and Theo de Raadt]
*) Fix BN_rand_range bug pointed out by Dominikus Scherkl *) Fix BN_rand_range bug pointed out by Dominikus Scherkl
<Dominikus.Scherkl@biodata.com>. (The previous implementation <Dominikus.Scherkl@biodata.com>. (The previous implementation
worked incorrectly for those cases where range = 10..._2 and worked incorrectly for those cases where range = 10..._2 and
......
...@@ -148,7 +148,6 @@ ...@@ -148,7 +148,6 @@
#include <signal.h> #include <signal.h>
#include <stdio.h> #include <stdio.h>
#include <string.h> #include <string.h>
#include <setjmp.h>
#include <errno.h> #include <errno.h>
#ifdef OPENSSL_SYS_VMS /* prototypes for sys$whatever */ #ifdef OPENSSL_SYS_VMS /* prototypes for sys$whatever */
...@@ -256,7 +255,6 @@ static struct sigaction savsig[NX509_SIG]; ...@@ -256,7 +255,6 @@ static struct sigaction savsig[NX509_SIG];
#else #else
static void (*savsig[NX509_SIG])(int ); static void (*savsig[NX509_SIG])(int );
#endif #endif
static jmp_buf save;
#ifdef OPENSSL_SYS_VMS #ifdef OPENSSL_SYS_VMS
static struct IOSB iosb; static struct IOSB iosb;
...@@ -374,6 +372,8 @@ static void read_till_nl(FILE *in) ...@@ -374,6 +372,8 @@ static void read_till_nl(FILE *in)
} while (strchr(buf,'\n') == NULL); } while (strchr(buf,'\n') == NULL);
} }
static sig_atomic_t intr_signal;
static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl) static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
{ {
static int ps; static int ps;
...@@ -383,29 +383,31 @@ static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl) ...@@ -383,29 +383,31 @@ static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
char *p; char *p;
#ifndef OPENSSL_SYS_WIN16 #ifndef OPENSSL_SYS_WIN16
if ((ok = setjmp(save))) intr_signal=0;
{
if (ok == 1) ok=0;
goto error;
}
ok=0; ok=0;
ps=0; ps=0;
pushsig(); pushsig();
ps=1; ps=1;
if (!echo) noecho_console(ui); if (!echo && !noecho_console(ui))
goto error;
ps=2; ps=2;
result[0]='\0'; result[0]='\0';
#ifdef OPENSSL_SYS_MSDOS #ifdef OPENSSL_SYS_MSDOS
if (!echo) if (!echo)
{
noecho_fgets(result,maxsize,tty_in); noecho_fgets(result,maxsize,tty_in);
p=result; /* FIXME: noecho_fgets doesn't return errors */
}
else else
fgets(result,maxsize,tty_in); p=fgets(result,maxsize,tty_in);
#else #else
fgets(result,maxsize,tty_in); p=fgets(result,maxsize,tty_in);
#endif #endif
if(!p)
goto error;
if (feof(tty_in)) goto error; if (feof(tty_in)) goto error;
if (ferror(tty_in)) goto error; if (ferror(tty_in)) goto error;
if ((p=(char *)strchr(result,'\n')) != NULL) if ((p=(char *)strchr(result,'\n')) != NULL)
...@@ -419,9 +421,11 @@ static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl) ...@@ -419,9 +421,11 @@ static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
ok=1; ok=1;
error: error:
if (intr_signal == SIGINT)
ok=-1;
if (!echo) fprintf(tty_out,"\n"); if (!echo) fprintf(tty_out,"\n");
if (ps >= 2 && !echo) if (ps >= 2 && !echo && !echo_console(ui))
echo_console(ui); ok=0;
if (ps >= 1) if (ps >= 1)
popsig(); popsig();
...@@ -602,18 +606,9 @@ static void popsig(void) ...@@ -602,18 +606,9 @@ static void popsig(void)
static void recsig(int i) static void recsig(int i)
{ {
switch(i) intr_signal=i;
{
case SIGINT:
longjmp(save,-1);
break;
default:
break;
}
longjmp(save,1);
} }
/* Internal functions specific for Windows */ /* Internal functions specific for Windows */
#if defined(OPENSSL_SYS_MSDOS) && !defined(OPENSSL_SYS_WIN16) #if defined(OPENSSL_SYS_MSDOS) && !defined(OPENSSL_SYS_WIN16)
static int noecho_fgets(char *buf, int size, FILE *tty) static int noecho_fgets(char *buf, int size, FILE *tty)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册