Menu

#14 Fixes for openssl 1.0.1i

Unstable_(example)
closed
nobody
None
5
2018-01-06
2014-08-12
No

Fixes following application error due to change in openssl 1.0.1i:

Errors
error:0D0C40D8:asn1 encoding routines:c2i_ASN1_OBJECT:invalid object encoding error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error error:0D0C40D8:asn1 encoding routines:c2i_ASN1_OBJECT:invalid object encoding error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error error:0D0C40D8:asn1 encoding routines:c2i_ASN1_OBJECT:invalid object encoding error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error error:0D0C40D8:asn1 encoding routines:c2i_ASN1_OBJECT:invalid object encoding error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error error:0D0C40D8:asn1 encoding routines:c2i_ASN1_OBJECT:invalid object encoding error:0D08303A:asn1 encoding routines:ASN1_TEMPLATE_NOEXP_D2I:nested asn1 error


Due to openssl 1.0.1i change:

commit 03b04ddac162c7b7fa3c57eadccc5a583a00d291
Author: Emilia Kasper emilia@openssl.org
Date: Wed Jul 2 19:02:33 2014 +0200

Fix OID handling:

- Upon parsing, reject OIDs with invalid base-128 encoding.
- Always NUL-terminate the destination buffer in OBJ_obj2txt printing function.

CVE-2014-3508

Reviewed-by: Dr. Stephen Henson <steve@openssl.org>
Reviewed-by: Kurt Roeckx <kurt@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>

1 Attachments

Discussion

  • Christian Hohnstaedt

    • status: open --> closed
     
  • Christian Hohnstaedt

    Has long been integrated in xca 1.0.0

    commit 4f7cd417320215c8ed3567536cbf2ca008946c38
    Author: Oliver Winker oliver@oli1170.net
    Date: Tue Aug 12 19:08:05 2014 +0200

    Fix for openssl 1.0.1i