Blame SOURCES/freeradius-FR-GV-201-check-input-output-length-in-make_secret.patch

653d32
From 8af41abbd3c0b078425963d88494cfa4e22627e5 Mon Sep 17 00:00:00 2001
653d32
From: "Alan T. DeKok" <aland@freeradius.org>
653d32
Date: Tue, 4 Jul 2017 10:12:09 -0400
653d32
Subject: [PATCH] FR-GV-201 - check input / output length in make_secret()
653d32
653d32
---
653d32
 src/lib/radius.c | 17 +++++++++++------
653d32
 1 file changed, 11 insertions(+), 6 deletions(-)
653d32
653d32
diff --git a/src/lib/radius.c b/src/lib/radius.c
653d32
index b9f0f59c9..62ec11c7a 100644
653d32
--- a/src/lib/radius.c
653d32
+++ b/src/lib/radius.c
653d32
@@ -542,17 +542,17 @@ static ssize_t rad_recvfrom(int sockfd, RADIUS_PACKET *packet, int flags,
653d32
  * encrypting passwords to RADIUS.
653d32
  */
653d32
 static void make_secret(uint8_t *digest, uint8_t const *vector,
653d32
-			char const *secret, uint8_t const *value)
653d32
+			char const *secret, uint8_t const *value, size_t length)
653d32
 {
653d32
 	FR_MD5_CTX context;
653d32
-	int	     i;
653d32
+	size_t	     i;
653d32
 
653d32
 	fr_md5_init(&context);
653d32
 	fr_md5_update(&context, vector, AUTH_VECTOR_LEN);
653d32
 	fr_md5_update(&context, (uint8_t const *) secret, strlen(secret));
653d32
 	fr_md5_final(digest, &context);
653d32
 
653d32
-	for ( i = 0; i < AUTH_VECTOR_LEN; i++ ) {
653d32
+	for ( i = 0; i < length; i++ ) {
653d32
 		digest[i] ^= value[i];
653d32
 	}
653d32
 }
653d32
@@ -1010,8 +1010,8 @@ static ssize_t vp2data_any(RADIUS_PACKET const *packet,
653d32
 		 *	always fits.
653d32
 		 */
653d32
 	case FLAG_ENCRYPT_ASCEND_SECRET:
653d32
-		if (len != 16) return 0;
653d32
-		make_secret(ptr, packet->vector, secret, data);
653d32
+		if (len > AUTH_VECTOR_LEN) len = AUTH_VECTOR_LEN;
653d32
+		make_secret(ptr, packet->vector, secret, data, len);
653d32
 		len = AUTH_VECTOR_LEN;
653d32
 		break;
653d32
 
653d32
@@ -3769,9 +3769,14 @@ ssize_t data2vp(TALLOC_CTX *ctx,
653d32
 				goto raw;
653d32
 			} else {
653d32
 				uint8_t my_digest[AUTH_VECTOR_LEN];
653d32
+				size_t secret_len;
653d32
+
653d32
+				secret_len = datalen;
653d32
+				if (secret_len > AUTH_VECTOR_LEN) secret_len = AUTH_VECTOR_LEN;
653d32
+
653d32
 				make_secret(my_digest,
653d32
 					    original->vector,
653d32
-					    secret, data);
653d32
+					    secret, data, secret_len);
653d32
 				memcpy(buffer, my_digest,
653d32
 				       AUTH_VECTOR_LEN );
653d32
 				buffer[AUTH_VECTOR_LEN] = '\0';
653d32
-- 
653d32
2.13.2
653d32