[openssl] master update
shane.lontis at oracle.com
shane.lontis at oracle.com
Tue Jun 30 01:53:08 UTC 2020
The branch master has been updated
via 9beffaf695b7ed5a7198496036b9aed87d598e51 (commit)
from 2c9ba46c90e9d25040260bbdc43e87921f08c788 (commit)
- Log -----------------------------------------------------------------
commit 9beffaf695b7ed5a7198496036b9aed87d598e51
Author: Shane Lontis <shane.lontis at oracle.com>
Date: Tue Jun 23 12:30:40 2020 +1000
Fix CID-1464802
Improper use of negative value (It just needs to pass zero instead of -1).
Reviewed-by: Tomas Mraz <tmraz at fedoraproject.org>
Reviewed-by: Matthias St. Pierre <Matthias.St.Pierre at ncp-e.com>
(Merged from https://github.com/openssl/openssl/pull/12237)
-----------------------------------------------------------------------
Summary of changes:
crypto/dsa/dsa_gen.c | 2 +-
crypto/ffc/ffc_params_generate.c | 8 ++++----
2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/crypto/dsa/dsa_gen.c b/crypto/dsa/dsa_gen.c
index 9d5e91de29..94b3da8754 100644
--- a/crypto/dsa/dsa_gen.c
+++ b/crypto/dsa/dsa_gen.c
@@ -63,7 +63,7 @@ int DSA_generate_parameters_ex(DSA *dsa, int bits,
return 0;
} else {
if (!dsa_generate_ffc_parameters(dsa, DSA_PARAMGEN_TYPE_FIPS_186_4,
- bits, -1, cb))
+ bits, 0, cb))
return 0;
}
diff --git a/crypto/ffc/ffc_params_generate.c b/crypto/ffc/ffc_params_generate.c
index b3ab476f3f..325eb6768f 100644
--- a/crypto/ffc/ffc_params_generate.c
+++ b/crypto/ffc/ffc_params_generate.c
@@ -504,7 +504,7 @@ int ffc_params_FIPS186_4_gen_verify(OPENSSL_CTX *libctx, FFC_PARAMS *params,
if (params->mdname != NULL) {
md = EVP_MD_fetch(libctx, params->mdname, params->mdprops);
} else {
- if (N <= 0)
+ if (N == 0)
N = (L >= 2048 ? SHA256_DIGEST_LENGTH : SHA_DIGEST_LENGTH) * 8;
md = EVP_MD_fetch(libctx, default_mdname(N), NULL);
}
@@ -514,7 +514,7 @@ int ffc_params_FIPS186_4_gen_verify(OPENSSL_CTX *libctx, FFC_PARAMS *params,
if (mdsize <= 0)
goto err;
- if (N <= 0)
+ if (N == 0)
N = mdsize * 8;
qsize = N >> 3;
@@ -790,13 +790,13 @@ int ffc_params_FIPS186_2_gen_verify(OPENSSL_CTX *libctx, FFC_PARAMS *params,
if (params->mdname != NULL) {
md = EVP_MD_fetch(libctx, params->mdname, params->mdprops);
} else {
- if (N <= 0)
+ if (N == 0)
N = (L >= 2048 ? SHA256_DIGEST_LENGTH : SHA_DIGEST_LENGTH) * 8;
md = EVP_MD_fetch(libctx, default_mdname(N), NULL);
}
if (md == NULL)
goto err;
- if (N <= 0)
+ if (N == 0)
N = EVP_MD_size(md) * 8;
qsize = N >> 3;
More information about the openssl-commits
mailing list