diff options
author | delphij <delphij@FreeBSD.org> | 2013-01-02 20:56:53 +0000 |
---|---|---|
committer | delphij <delphij@FreeBSD.org> | 2013-01-02 20:56:53 +0000 |
commit | 90d033541aadf8dd14ea582d23a845e6345d9687 (patch) | |
tree | c1f23b0a4b978801cc507218f72456c626277b20 /crypto | |
parent | 532b4084cb8cac5e6d91d42aa6a497dd4ba4a4f5 (diff) | |
download | FreeBSD-src-90d033541aadf8dd14ea582d23a845e6345d9687.zip FreeBSD-src-90d033541aadf8dd14ea582d23a845e6345d9687.tar.gz |
Integrate OpenSSL changeset 22950 (appro):
bn_word.c: fix overflow bug in BN_add_word.
Diffstat (limited to 'crypto')
-rw-r--r-- | crypto/bn/bn_word.c | 25 |
1 files changed, 8 insertions, 17 deletions
diff --git a/crypto/bn/bn_word.c b/crypto/bn/bn_word.c index ee7b87c..de83a15 100644 --- a/crypto/bn/bn_word.c +++ b/crypto/bn/bn_word.c @@ -144,26 +144,17 @@ int BN_add_word(BIGNUM *a, BN_ULONG w) a->neg=!(a->neg); return(i); } - /* Only expand (and risk failing) if it's possibly necessary */ - if (((BN_ULONG)(a->d[a->top - 1] + 1) == 0) && - (bn_wexpand(a,a->top+1) == NULL)) - return(0); - i=0; - for (;;) + for (i=0;w!=0 && i<a->top;i++) { - if (i >= a->top) - l=w; - else - l=(a->d[i]+w)&BN_MASK2; - a->d[i]=l; - if (w > l) - w=1; - else - break; - i++; + a->d[i] = l = (a->d[i]+w)&BN_MASK2; + w = (w>l)?1:0; } - if (i >= a->top) + if (w && i==a->top) + { + if (bn_wexpand(a,a->top+1) == NULL) return 0; a->top++; + a->d[i]=w; + } bn_check_top(a); return(1); } |