Adding check for invalid SAN ext with no entries

This commit is contained in:
Eric Blankenhorn
2020-04-09 16:49:52 -05:00
parent 2bf9dc4037
commit 7d82c4e3f2

View File

@ -7635,6 +7635,13 @@ static int DecodeAltNames(const byte* input, int sz, DecodedCert* cert)
return ASN_PARSE_E;
}
if (length == 0) {
/* RFC 5280 4.2.1.6. Subject Alternative Name
If the subjectAltName extension is present, the sequence MUST
contain at least one entry. */
return ASN_PARSE_E;
}
cert->weOwnAltNames = 1;
while (length > 0) {