HomeClusterLabs Projects
Diffusion Booth 98b4284d1701

auth: Check result of gcrypt gcry_md_get_algo_dlen

Description

auth: Check result of gcrypt gcry_md_get_algo_dlen

When unknown hash is passed to gcry_md_get_algo_dlen 0 is returned. This
value is then used for memcmp so wrong hmac might be accepted as
correct.

Signed-off-by: Jan Friesse <jfriesse@redhat.com>

Details

Provenance
jfriesseAuthored on Feb 21 2024, 12:12 PM
Parents
rB43eaf0e82b14: attr: Fix reading of server_reply
Branches
Unknown
Tags
Unknown

Event Timeline