3 ms·
quick question, I didn't look into the detail of the issue and novice on Rust as well - question is to whom already checked detail of the vulnerability, is this
by botplaysdice 4y ago
quick question, I didn't look into the detail of the issue and novice on Rust as well - question is to whom already checked detail of the vulnerability, is this bug kind of ones we can prevent if we're using Rust instead of C?
- formerly_proven 4y agoBog standard buffer overflow caused by incorrect bounds checking. Yes.
- nequo 4y agoIndeed. For illustration, the Ubuntu commits that fix the two CVEs: https://git.launchpad.net/ubuntu/+source/openssl/commit/?h=applied/ubuntu/jammy-security&id=d6ccc4dfd3b75fa0323c9f49303f9d1610923036 https://git.launchpad.net/ubuntu/+source/openssl/commit/?h=a... - if (written_out > max_out) + if (written_out >= max_out) [...] https://git.launchpad.net/ubuntu/+source/openssl/commit/?id=293ec060164a1f4cbf7a881165c923bbd9428229 https://git.launchpad.net/ubuntu/+source/openssl/commit/?id=... - if (tmpptr != NULL) - PUSHC('.'); + PUSHC(tmpptr != NULL ? '.' : '\0'); - char a_ulabel[LABEL_BUF_SIZE]; + char a_ulabel[LABEL_BUF_SIZE + 1]; https://git.launchpad.net/ubuntu/+source/openssl/commit/?id=3b0e1a39a7086f9fcfe9156f4a6d481953ec0af4 https://git.launchpad.net/ubuntu/+source/openssl/commit/?id=... - || type->origin == EVP_ORIG_METH) { + || (type != NULL && type->origin == EVP_ORIG_METH) + || (type == NULL && ctx->digest != NULL + && ctx->digest->origin == EVP_ORIG_METH)) { - || impl != NULL) { + || impl != NULL + || (cipher != NULL && cipher->origin == EVP_ORIG_METH) + || (cipher == NULL && ctx->cipher != NULL + && ctx->cipher->origin == EVP_ORIG_METH)) {