projects
/
oweals
/
openssl.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
| inline |
side by side
Fix undefined behaviour in e_aes_cbc_hmac_sha256.c and e_aes_cbc_hmac_sha1.c
[oweals/openssl.git]
/
crypto
/
ct
/
ct_vfy.c
diff --git
a/crypto/ct/ct_vfy.c
b/crypto/ct/ct_vfy.c
index 724f65579bca1f3f7a668fe94bb97f323fdc42f3..cabcf5782aa445a49a2a771d1354172a3b818c12 100644
(file)
--- a/
crypto/ct/ct_vfy.c
+++ b/
crypto/ct/ct_vfy.c
@@
-113,6
+113,10
@@
int SCT_CTX_verify(const SCT_CTX *sctx, const SCT *sct)
CTerr(CT_F_SCT_CTX_VERIFY, CT_R_SCT_LOG_ID_MISMATCH);
return 0;
}
+ if (sct->timestamp > sctx->epoch_time_in_ms) {
+ CTerr(CT_F_SCT_CTX_VERIFY, CT_R_SCT_FUTURE_TIMESTAMP);
+ return 0;
+ }
ctx = EVP_MD_CTX_new();
if (ctx == NULL)