agent: Fix length test in sshcontrol parser.
authorWerner Koch <wk@gnupg.org>
Sun, 15 Mar 2015 12:04:48 +0000 (13:04 +0100)
committerWerner Koch <wk@gnupg.org>
Sun, 15 Mar 2015 12:04:48 +0000 (13:04 +0100)
commit3529dd8bb5bafc4e02915648d5f409bd27a9cc37
tree9ee1854bee1818226808ebc8f78d81edfb275924
parent95415bdec77a608e6052ba3e2a5d857a8e8f7689
agent: Fix length test in sshcontrol parser.

* agent/command-ssh.c (ssh_search_control_file): Check S before
upcasing it.
--

In contradiction to the comment we did not check the length of HEXGRIP
and thus the GPG_ERR_INV_LENGTH was never triggered.

Detected by Stack 0.3:

  bug: anti-simplify
  model: |
    %cmp8 = icmp ne i32 %i.0, 40, !dbg !986
    -->  false
  stack:
    - /home/wk/s/gnupg/agent/command-ssh.c:1226:0
  ncore: 2
  core:
    - /home/wk/s/gnupg/agent/command-ssh.c:1225:0
      - buffer overflow
    - /home/wk/s/gnupg/agent/command-ssh.c:1225:0
      - buffer overflow
agent/command-ssh.c