Disallow all special operators once groups are used.
+ and - should also be forbidden. Any operation other than appending will mix up the in_group bits and give unexpected behavior. Change-Id: Ieaebb9ee6393aa36243d0765e45cae667f977ef5 Reviewed-on: https://boringssl-review.googlesource.com/1803 Reviewed-by: Adam Langley <agl@google.com>
This commit is contained in:
committed by
Adam Langley
parent
2a5ea98a46
commit
37d924640a
+10
-12
@@ -761,20 +761,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
{ rule = CIPHER_DEL; l++; }
|
||||
else if (ch == '+')
|
||||
{ rule = CIPHER_ORD; l++; }
|
||||
else if (ch == '!' && has_group)
|
||||
{
|
||||
OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
retval = found = in_group = 0;
|
||||
break;
|
||||
}
|
||||
else if (ch == '!')
|
||||
{ rule = CIPHER_KILL; l++; }
|
||||
else if (ch == '@' && has_group)
|
||||
{
|
||||
OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
retval = found = in_group = 0;
|
||||
break;
|
||||
}
|
||||
else if (ch == '@')
|
||||
{ rule = CIPHER_SPECIAL; l++; }
|
||||
else if (ch == '[')
|
||||
@@ -793,6 +781,16 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
else
|
||||
{ rule = CIPHER_ADD; }
|
||||
|
||||
/* If preference groups are enabled, the only legal
|
||||
* operator is +. Otherwise the in_group bits will get
|
||||
* mixed up. */
|
||||
if (has_group && rule != CIPHER_ADD)
|
||||
{
|
||||
OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
retval = found = in_group = 0;
|
||||
break;
|
||||
}
|
||||
|
||||
if (ITEM_SEP(ch))
|
||||
{
|
||||
l++;
|
||||
|
||||
@@ -179,6 +179,11 @@ static const char *kBadRules[] = {
|
||||
"BOGUS",
|
||||
/* Invalid command. */
|
||||
"?BAR",
|
||||
/* Special operators are not allowed if groups are used. */
|
||||
"[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:+FOO",
|
||||
"[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:!FOO",
|
||||
"[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:-FOO",
|
||||
"[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:@STRENGTH",
|
||||
NULL,
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user