From 392ce7db1eccf5e2eacb074195ea7f5016f70259 Mon Sep 17 00:00:00 2001 From: Jack Lloyd Date: Sun, 2 Aug 2015 23:43:12 -0400 Subject: Fix two crashes in the BER decoder found with afl. One a read at 0 of an empty vector, the other causing allocation of an arbitrary amount of memory. --- src/tests/data/fuzz/x509/afl_007.pem | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 src/tests/data/fuzz/x509/afl_007.pem (limited to 'src/tests/data/fuzz/x509/afl_007.pem') diff --git a/src/tests/data/fuzz/x509/afl_007.pem b/src/tests/data/fuzz/x509/afl_007.pem new file mode 100644 index 000000000..30145a8fa --- /dev/null +++ b/src/tests/data/fuzz/x509/afl_007.pem @@ -0,0 +1,13 @@ +-----BEGIN CERTIFICATE----- +MICAIN CAWMCAgGjMA0GCSqGSIb3DQEBBAUAMEUxCzAJBgNVBAYTAlVTMRgwFgYD +VQQKEw9HVEUgQ29ycG9yYXRpb24xHDAaBgNVBAMTE0dURSBDeWJlclRydXN0IFJv +b3QwHhcNOTYwMjIzMjMwMTAwWhcNMDYwMjIzMjM1OTAwWjBFMQswCQYDVQQGEwJV +UzEYMBYGA1UEChMPR1RFIENvcnBvcmF0aW9uMRwwGgYDVQQDExNHVEUgQ3liZXJU +cnVzdCBSb290MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC45k+625h8cXyv +RLfTD0bZZOWTwUKOx7pJjTUteueLveUFMVnGsS8KDPufpz+iCWaEVh43KRuH6X4M +ypqfpX/1FZSj1aJGgthoTNE3FQZor734sLPwKfWVWgkWYXcKIiXUT0Wqx73llt/5 +1KiOQswkwB6RJ0q1bQaAYznEol44AwIDAQABMA0GCSqGSIb3DQEBBAUAA4GBABKz +dcZfHeFhVYAA1IFLezEPI2PnPfMD+fQ2qLvZ46WXTeorKeDWanOB5sCJo9Px4KWl +IjeaY8JIILTbcuPI9tl8vrGvU9oUtCG41tWW4/5ODFlitppK+ULdjG+BqXH/9Apy +bW1EDp3zdHSo1TRJ6V6e6bR64eVaH4QwnNOfpSXY +-----END CERTIFICATE----- \ No newline at end of file -- cgit v1.2.3