summaryrefslogtreecommitdiff
path: root/kexdhs.c
diff options
context:
space:
mode:
authorDarren Tucker <dtucker@zip.com.au>2009-06-21 19:00:20 +1000
committerDarren Tucker <dtucker@zip.com.au>2009-06-21 19:00:20 +1000
commit6ae35ac5762b6abcbd416e7db9246e730b401f10 (patch)
treebbb2d11b32d447355ef49ff3bfe42488e0d613d1 /kexdhs.c
parent7b935c79f4f31da21989cc441caee247af417b3b (diff)
- dtucker@cvs.openbsd.org 2009/06/21 07:37:15
[kexdhs.c kexgexs.c] abort if key_sign fails, preventing possible null deref. Based on report from Paolo Ganci, ok markus@ djm@
Diffstat (limited to 'kexdhs.c')
-rw-r--r--kexdhs.c6
1 files changed, 4 insertions, 2 deletions
diff --git a/kexdhs.c b/kexdhs.c
index 861708818..a6719f672 100644
--- a/kexdhs.c
+++ b/kexdhs.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: kexdhs.c,v 1.9 2006/11/06 21:25:28 markus Exp $ */ 1/* $OpenBSD: kexdhs.c,v 1.10 2009/06/21 07:37:15 dtucker Exp $ */
2/* 2/*
3 * Copyright (c) 2001 Markus Friedl. All rights reserved. 3 * Copyright (c) 2001 Markus Friedl. All rights reserved.
4 * 4 *
@@ -137,7 +137,9 @@ kexdh_server(Kex *kex)
137 } 137 }
138 138
139 /* sign H */ 139 /* sign H */
140 PRIVSEP(key_sign(server_host_key, &signature, &slen, hash, hashlen)); 140 if (PRIVSEP(key_sign(server_host_key, &signature, &slen, hash,
141 hashlen)) < 0)
142 fatal("kexdh_server: key_sign failed");
141 143
142 /* destroy_sensitive_data(); */ 144 /* destroy_sensitive_data(); */
143 145