[openssl/openssl] 25dd78: CMS_decrypt*(): fix misconceptions and mem leak

David von Oheimb noreply at github.com
Fri Nov 25 08:09:01 UTC 2022


  Branch: refs/heads/master
  Home:   https://github.com/openssl/openssl
  Commit: 25dd78048b69c2a780ab1a5378b62447c77a5e75
      https://github.com/openssl/openssl/commit/25dd78048b69c2a780ab1a5378b62447c77a5e75
  Author: Dr. David von Oheimb <David.von.Oheimb at siemens.com>
  Date:   2022-11-25 (Fri, 25 Nov 2022)

  Changed paths:
    M crypto/cms/cms_env.c
    M crypto/cms/cms_smime.c
    M doc/man3/CMS_EncryptedData_decrypt.pod
    M doc/man3/CMS_decrypt.pod

  Log Message:
  -----------
  CMS_decrypt*(): fix misconceptions and mem leak

Reviewed-by: Tomas Mraz <tomas at openssl.org>
Reviewed-by: Paul Dale <pauli at openssl.org>
Reviewed-by: David von Oheimb <david.von.oheimb at siemens.com>
(Merged from https://github.com/openssl/openssl/pull/19222)


  Commit: 911045afda06bec038ccd15e9f849bff05b6f1ee
      https://github.com/openssl/openssl/commit/911045afda06bec038ccd15e9f849bff05b6f1ee
  Author: Dr. David von Oheimb <David.von.Oheimb at siemens.com>
  Date:   2022-11-25 (Fri, 25 Nov 2022)

  Changed paths:
    M crypto/cms/cms_smime.c

  Log Message:
  -----------
  CMS_decrypt_set1_password(): prevent mem leak on any previously set decryption key

Reviewed-by: Tomas Mraz <tomas at openssl.org>
Reviewed-by: Paul Dale <pauli at openssl.org>
Reviewed-by: David von Oheimb <david.von.oheimb at siemens.com>
(Merged from https://github.com/openssl/openssl/pull/19222)


  Commit: 60ea150b1f535e4f0c76e23af4130b3861fabf54
      https://github.com/openssl/openssl/commit/60ea150b1f535e4f0c76e23af4130b3861fabf54
  Author: Dr. David von Oheimb <David.von.Oheimb at siemens.com>
  Date:   2022-11-25 (Fri, 25 Nov 2022)

  Changed paths:
    M crypto/cms/cms_smime.c

  Log Message:
  -----------
  CMS_decrypt_set1_*(): remove misleading error queue entry when recipient mismatch was not the issue

Reviewed-by: Tomas Mraz <tomas at openssl.org>
Reviewed-by: Paul Dale <pauli at openssl.org>
Reviewed-by: David von Oheimb <david.von.oheimb at siemens.com>
(Merged from https://github.com/openssl/openssl/pull/19222)


Compare: https://github.com/openssl/openssl/compare/0b7ad5d928f9...60ea150b1f53


More information about the openssl-commits mailing list