mirror of
https://git.libssh.org/projects/libssh.git
synced 2026-02-07 10:40:28 +09:00
CVE-2023-6918: Systematically check return values when calculating digests
with all crypto backends Signed-off-by: Jakub Jelen <jjelen@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
This commit is contained in:
committed by
Andreas Schneider
parent
882d9cb5c8
commit
a45a3c940d
144
src/libgcrypt.c
144
src/libgcrypt.c
@@ -68,18 +68,35 @@ SHACTX sha1_init(void) {
|
||||
return ctx;
|
||||
}
|
||||
|
||||
void sha1_update(SHACTX c, const void *data, unsigned long len) {
|
||||
void
|
||||
sha1_ctx_free(SHACTX c)
|
||||
{
|
||||
gcry_md_close(c);
|
||||
}
|
||||
|
||||
int sha1_update(SHACTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c, data, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha1_final(unsigned char *md, SHACTX c) {
|
||||
gcry_md_final(c);
|
||||
memcpy(md, gcry_md_read(c, 0), SHA_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
int sha1_final(unsigned char *md, SHACTX c)
|
||||
{
|
||||
unsigned char *tmp = NULL;
|
||||
|
||||
gcry_md_final(c);
|
||||
tmp = gcry_md_read(c, 0);
|
||||
if (tmp == NULL) {
|
||||
gcry_md_close(c);
|
||||
return SSH_ERROR;
|
||||
}
|
||||
memcpy(md, tmp, SHA_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha1(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
int sha1(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
gcry_md_hash_buffer(GCRY_MD_SHA1, hash, digest, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
|
||||
@@ -90,18 +107,35 @@ SHA256CTX sha256_init(void) {
|
||||
return ctx;
|
||||
}
|
||||
|
||||
void sha256_update(SHACTX c, const void *data, unsigned long len) {
|
||||
void
|
||||
sha256_ctx_free(SHA256CTX c)
|
||||
{
|
||||
gcry_md_close(c);
|
||||
}
|
||||
|
||||
int sha256_update(SHACTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c, data, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha256_final(unsigned char *md, SHACTX c) {
|
||||
gcry_md_final(c);
|
||||
memcpy(md, gcry_md_read(c, 0), SHA256_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
int sha256_final(unsigned char *md, SHACTX c)
|
||||
{
|
||||
unsigned char *tmp = NULL;
|
||||
|
||||
gcry_md_final(c);
|
||||
tmp = gcry_md_read(c, 0);
|
||||
if (tmp == NULL) {
|
||||
gcry_md_close(c);
|
||||
return SSH_ERROR;
|
||||
}
|
||||
memcpy(md, tmp, SHA256_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha256(const unsigned char *digest, int len, unsigned char *hash){
|
||||
int sha256(const unsigned char *digest, int len, unsigned char *hash){
|
||||
gcry_md_hash_buffer(GCRY_MD_SHA256, hash, digest, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
SHA384CTX sha384_init(void) {
|
||||
@@ -111,18 +145,35 @@ SHA384CTX sha384_init(void) {
|
||||
return ctx;
|
||||
}
|
||||
|
||||
void sha384_update(SHACTX c, const void *data, unsigned long len) {
|
||||
void
|
||||
sha384_ctx_free(SHA384CTX c)
|
||||
{
|
||||
gcry_md_close(c);
|
||||
}
|
||||
|
||||
int sha384_update(SHACTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c, data, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha384_final(unsigned char *md, SHACTX c) {
|
||||
gcry_md_final(c);
|
||||
memcpy(md, gcry_md_read(c, 0), SHA384_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
int sha384_final(unsigned char *md, SHACTX c)
|
||||
{
|
||||
unsigned char *tmp = NULL;
|
||||
|
||||
gcry_md_final(c);
|
||||
tmp = gcry_md_read(c, 0);
|
||||
if (tmp == NULL) {
|
||||
gcry_md_close(c);
|
||||
return SSH_ERROR;
|
||||
}
|
||||
memcpy(md, tmp, SHA384_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha384(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
int sha384(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
gcry_md_hash_buffer(GCRY_MD_SHA384, hash, digest, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
SHA512CTX sha512_init(void) {
|
||||
@@ -132,18 +183,35 @@ SHA512CTX sha512_init(void) {
|
||||
return ctx;
|
||||
}
|
||||
|
||||
void sha512_update(SHACTX c, const void *data, unsigned long len) {
|
||||
void
|
||||
sha512_ctx_free(SHA512CTX c)
|
||||
{
|
||||
gcry_md_close(c);
|
||||
}
|
||||
|
||||
int sha512_update(SHACTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c, data, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha512_final(unsigned char *md, SHACTX c) {
|
||||
gcry_md_final(c);
|
||||
memcpy(md, gcry_md_read(c, 0), SHA512_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
int sha512_final(unsigned char *md, SHACTX c)
|
||||
{
|
||||
unsigned char *tmp = NULL;
|
||||
|
||||
gcry_md_final(c);
|
||||
tmp = gcry_md_read(c, 0);
|
||||
if (tmp == NULL) {
|
||||
gcry_md_close(c);
|
||||
return SSH_ERROR;
|
||||
}
|
||||
memcpy(md, tmp, SHA512_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
void sha512(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
int sha512(const unsigned char *digest, int len, unsigned char *hash) {
|
||||
gcry_md_hash_buffer(GCRY_MD_SHA512, hash, digest, len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
MD5CTX md5_init(void) {
|
||||
@@ -153,14 +221,30 @@ MD5CTX md5_init(void) {
|
||||
return c;
|
||||
}
|
||||
|
||||
void md5_update(MD5CTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c,data,len);
|
||||
void
|
||||
md5_ctx_free(MD5CTX c)
|
||||
{
|
||||
gcry_md_close(c);
|
||||
}
|
||||
|
||||
void md5_final(unsigned char *md, MD5CTX c) {
|
||||
gcry_md_final(c);
|
||||
memcpy(md, gcry_md_read(c, 0), MD5_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
int md5_update(MD5CTX c, const void *data, unsigned long len) {
|
||||
gcry_md_write(c,data,len);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
int md5_final(unsigned char *md, MD5CTX c)
|
||||
{
|
||||
unsigned char *tmp = NULL;
|
||||
|
||||
gcry_md_final(c);
|
||||
tmp = gcry_md_read(c, 0);
|
||||
if (tmp == NULL) {
|
||||
gcry_md_close(c);
|
||||
return SSH_ERROR;
|
||||
}
|
||||
memcpy(md, tmp, MD5_DIGEST_LEN);
|
||||
gcry_md_close(c);
|
||||
return SSH_OK;
|
||||
}
|
||||
|
||||
int ssh_kdf(struct ssh_crypto_struct *crypto,
|
||||
|
||||
Reference in New Issue
Block a user