Closed Bug 1953429 Opened 1 year ago Closed 1 year ago

encode_kind == SEC_ASN1_INLINE && !optional, at ../../lib/util/secasn1d.c:584

Categories

(NSS :: Test, defect)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mdauer, Assigned: mdauer)

References

Details

Attachments

(2 files)

The ASN1 decoder does not support templates using SEC_ASN1_INLINE together with SEC_ASN1_OPTIONAL. Remove those templates from the asn1 fuzz target.

The ASN1 decoder does not support templates that use SEC_ASN1_INLINE and SEC_ASN1_OPTIONAL together.

Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Status: RESOLVED → REOPENED
Resolution: FIXED → ---

The ASN1 decoder does not support templates that use SEC_ASN1_INLINE and SEC_ASN1_OPTIONAL together. These are used by the QuickDER fuzz target.

Status: REOPENED → RESOLVED
Closed: 1 year ago → 1 year ago
Resolution: --- → FIXED
See Also: → 1955971

Why did you consider it a sufficient fix to simply remove the template from fuzzing?

Is it because these templates are never used with the secasn1d decoder?

Yeah, I found Bug 289649 which states:

[...] CRLs are normally decoded with the QuickDER decode, which supports this syntax without limitations.

I looked through searchfox and couldn't find CRL templates used with the ASN1 decoder, thus figured it should be fine to remove them. We use these templates in the QuickDER decoder fuzz target.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: