diff options
author | Damien Miller <djm@mindrot.org> | 2010-07-16 13:57:51 +1000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2010-07-16 13:57:51 +1000 |
commit | 8a0268f1b3f62292d4124f8d158e0587c4f7c330 (patch) | |
tree | 43493a3202569a2939f5616127d9de8689613a7b /key.c | |
parent | d0244d498ba970b9d9348429eaf7a4a0ef2b903c (diff) |
- djm@cvs.openbsd.org 2010/07/13 11:52:06
[auth-rsa.c channels.c jpake.c key.c misc.c misc.h monitor.c]
[packet.c ssh-rsa.c]
implement a timing_safe_cmp() function to compare memory without leaking
timing information by short-circuiting like memcmp() and use it for
some of the more sensitive comparisons (though nothing high-value was
readily attackable anyway); "looks ok" markus@
Diffstat (limited to 'key.c')
-rw-r--r-- | key.c | 5 |
1 files changed, 3 insertions, 2 deletions
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: key.c,v 1.88 2010/05/07 11:30:29 djm Exp $ */ | 1 | /* $OpenBSD: key.c,v 1.89 2010/07/13 11:52:06 djm Exp $ */ |
2 | /* | 2 | /* |
3 | * read_bignum(): | 3 | * read_bignum(): |
4 | * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland | 4 | * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland |
@@ -52,6 +52,7 @@ | |||
52 | #include "uuencode.h" | 52 | #include "uuencode.h" |
53 | #include "buffer.h" | 53 | #include "buffer.h" |
54 | #include "log.h" | 54 | #include "log.h" |
55 | #include "misc.h" | ||
55 | #include "ssh2.h" | 56 | #include "ssh2.h" |
56 | 57 | ||
57 | static struct KeyCert * | 58 | static struct KeyCert * |
@@ -227,7 +228,7 @@ cert_compare(struct KeyCert *a, struct KeyCert *b) | |||
227 | return 0; | 228 | return 0; |
228 | if (buffer_len(&a->certblob) != buffer_len(&b->certblob)) | 229 | if (buffer_len(&a->certblob) != buffer_len(&b->certblob)) |
229 | return 0; | 230 | return 0; |
230 | if (memcmp(buffer_ptr(&a->certblob), buffer_ptr(&b->certblob), | 231 | if (timing_safe_cmp(buffer_ptr(&a->certblob), buffer_ptr(&b->certblob), |
231 | buffer_len(&a->certblob)) != 0) | 232 | buffer_len(&a->certblob)) != 0) |
232 | return 0; | 233 | return 0; |
233 | return 1; | 234 | return 1; |