encode_kind == SEC_ASN1_INLINE && !optional, at ../../lib/util/secasn1d.c:584
Categories
(NSS :: Test, defect)
Tracking
(Not tracked)
People
(Reporter: mdauer, Assigned: mdauer)
References
Details
Attachments
(2 files)
The ASN1 decoder does not support templates using SEC_ASN1_INLINE together with SEC_ASN1_OPTIONAL. Remove those templates from the asn1 fuzz target.
| Assignee | ||
Comment 1•1 year ago
|
||
The ASN1 decoder does not support templates that use SEC_ASN1_INLINE and SEC_ASN1_OPTIONAL together.
Comment 2•1 year ago
|
||
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 3•1 year ago
|
||
The ASN1 decoder does not support templates that use SEC_ASN1_INLINE and SEC_ASN1_OPTIONAL together. These are used by the QuickDER fuzz target.
| Assignee | ||
Comment 4•1 year ago
|
||
Comment 5•1 year ago
|
||
Why did you consider it a sufficient fix to simply remove the template from fuzzing?
Is it because these templates are never used with the secasn1d decoder?
| Assignee | ||
Comment 6•1 year ago
|
||
Yeah, I found Bug 289649 which states:
[...] CRLs are normally decoded with the QuickDER decode, which supports this syntax without limitations.
I looked through searchfox and couldn't find CRL templates used with the ASN1 decoder, thus figured it should be fine to remove them. We use these templates in the QuickDER decoder fuzz target.
Description
•