3 ms·
The fix for OpenJDK (authored on Jan. 4th 22): https://github.com/openjdk/jdk/blob/e2f8ce9c3ff4518e070960bafa70ba780746aa5c/src/jdk.crypto.ec/share/classes/sun
by bertman 4y ago
The fix for OpenJDK (authored on Jan. 4th 22):
https://github.com/openjdk/jdk/blob/e2f8ce9c3ff4518e070960bafa70ba780746aa5c/src/jdk.crypto.ec/share/classes/sun/security/ec/ECDSAOperations.java#L225 https://github.com/openjdk/jdk/blob/e2f8ce9c3ff4518e070960ba...
- drexlspivey 4y agowith commit message “Improve ECDSA signature support” :D
- baobabKoodaa 4y agoI'm guessing the commit message is obscured to give people more time to update before it's exploited in the wild.
- sdhfkjwefs 4y agoWhy are there no tests?
- MrBuddyCasino 4y agoI spot no test or comment in the code on why this assertion is important.
- bertman 4y agoIt's literally what the whole bug is about. From OP's article: >This is why the very first check in the ECDSA verification algorithm is to ensure that r and s are both >= 1. Guess which check Java forgot?
- MrBuddyCasino 4y agoYes I just think it’s insane they fixed it without adding a test or comment.