diff options
author | Jack Lloyd <[email protected]> | 2016-11-28 05:51:53 -0500 |
---|---|---|
committer | Jack Lloyd <[email protected]> | 2016-11-28 05:51:53 -0500 |
commit | 8fce1edc0214b1149cbf4723322714f2e22032eb (patch) | |
tree | 1f5f56768ac821df8e62f86bfca8ad2e85cfc780 /src/utils | |
parent | 47e7c44c13a062f09649234475b9ded541e5283a (diff) |
Fix BER integer overflow (CVE-2016-9132)
Diffstat (limited to 'src/utils')
-rw-r--r-- | src/utils/info.txt | 1 | ||||
-rw-r--r-- | src/utils/safeint.h | 39 |
2 files changed, 40 insertions, 0 deletions
diff --git a/src/utils/info.txt b/src/utils/info.txt index 57b6a2740..bbca1985c 100644 --- a/src/utils/info.txt +++ b/src/utils/info.txt @@ -20,6 +20,7 @@ ct_utils.h mlock.h prefetch.h rounding.h +safeint.h stl_util.h xor_buf.h </header:internal> diff --git a/src/utils/safeint.h b/src/utils/safeint.h new file mode 100644 index 000000000..e0bd66232 --- /dev/null +++ b/src/utils/safeint.h @@ -0,0 +1,39 @@ +/* +* Safe(r) Integer Handling +* (C) 2016 Jack Lloyd +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#ifndef BOTAN_UTILS_SAFE_INT_H__ +#define BOTAN_UTILS_SAFE_INT_H__ + +#include <botan/exceptn.h> +#include <string> + +namespace Botan { + +class Integer_Overflow_Detected : public Exception + { + public: + Integer_Overflow_Detected(const std::string& file, int line) : + Exception("Integer overflow detected at " + file + ":" + std::to_string(line)) + {} + }; + +inline size_t checked_add(size_t x, size_t y, const char* file, int line) + { + // TODO: use __builtin_x_overflow on GCC and Clang + size_t z = x + y; + if(z < x) + { + throw Integer_Overflow_Detected(file, line); + } + return z; + } + +#define BOTAN_CHECKED_ADD(x,y) checked_add(x,y,__FILE__,__LINE__) + +} + +#endif |