Check for PK11_CreateContextBySymKey returning null

RESOLVED FIXED in mozilla31

Status

()

defect
RESOLVED FIXED
6 years ago
5 years ago

People

(Reporter: ekr, Assigned: bwc)

Tracking

unspecified
mozilla31
x86
macOS
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment, 1 obsolete attachment)

No description provided.
Group: core-security
See:
http://hg.mozilla.org/mozilla-central/annotate/fa098f9fe89c/media/mtransport/nricectx.cpp#l135

Marked security until we verify that this is just a null pointer dereference.
See:
http://hg.mozilla.org/mozilla-central/annotate/fa098f9fe89c/media/mtransport/nricectx.cpp#l135

Marked security until we verify that this is just a null pointer dereference.
Assignee: nobody → docfaraday
This is just a null pointer deref in PK11_DigestBegin.
Comment on attachment 8400229 [details] [diff] [review]
Check whether PK11_CreateContextBySymKey returns null

Review of attachment 8400229 [details] [diff] [review]:
-----------------------------------------------------------------

Also, we can unmark this as security, since this is just a null pointer member access.
Attachment #8400229 - Flags: review?(ekr)
Group: core-security
Comment on attachment 8400229 [details] [diff] [review]
Check whether PK11_CreateContextBySymKey returns null

Review of attachment 8400229 [details] [diff] [review]:
-----------------------------------------------------------------

Please revert this formatting change.

::: media/mtransport/nricectx.cpp
@@ +131,5 @@
>    if (!skey)
>      goto abort;
>  
>  
> +  hmac_ctx = PK11_CreateContextBySymKey(mech, CKA_SIGN, skey, &param);

Superfluous reformatting.
Attachment #8400229 - Flags: review?(ekr) → review+
Undo formatting change.
Attachment #8400229 - Attachment is obsolete: true
Keywords: checkin-needed
https://hg.mozilla.org/mozilla-central/rev/9814945feba2
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla31
You need to log in before you can comment on or make changes to this bug.