From 9fc8c8e0b6cd34f70c89024c7bd588fbb57e18ba Mon Sep 17 00:00:00 2001 From: JacobBarthelmeh Date: Mon, 16 Mar 2020 15:14:29 -0700 Subject: [PATCH] add space for null terminator and check on header pointer --- wolfcrypt/src/asn.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/wolfcrypt/src/asn.c b/wolfcrypt/src/asn.c index 58a726fe3..142cdf440 100644 --- a/wolfcrypt/src/asn.c +++ b/wolfcrypt/src/asn.c @@ -10434,8 +10434,8 @@ int PemToDer(const unsigned char* buff, long longSz, int type, #endif #endif #ifdef OPENSSL_EXTRA - char beginBuf[PEM_LINE_LEN]; - char endBuf[PEM_LINE_LEN]; + char beginBuf[PEM_LINE_LEN + 1]; /* add 1 for null terminator */ + char endBuf[PEM_LINE_LEN + 1]; /* add 1 for null terminator */ #endif WOLFSSL_ENTER("PemToDer"); @@ -10506,7 +10506,8 @@ int PemToDer(const unsigned char* buff, long longSz, int type, XSTR_SIZEOF(BEGIN_PRIV_KEY_PREFIX)) != 0) { headerEnd--; } - if (XSTRNCMP(headerEnd, BEGIN_PRIV_KEY_PREFIX, + if (headerEnd <= (char*)buff || + XSTRNCMP(headerEnd, BEGIN_PRIV_KEY_PREFIX, XSTR_SIZEOF(BEGIN_PRIV_KEY_PREFIX)) != 0 || beginEnd - headerEnd > PEM_LINE_LEN) { WOLFSSL_MSG("Couldn't find PEM header");