From: Matt Caswell Date: Tue, 10 Feb 2015 13:15:25 +0000 (+0000) Subject: Fix HMAC to pass invalid key len test X-Git-Tag: OpenSSL_1_0_2b~149 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=ddbf312fb4ae31eb2e87af736e0a3b5b347d736a;p=oweals%2Fopenssl.git Fix HMAC to pass invalid key len test Reviewed-by: Richard Levitte --- diff --git a/crypto/hmac/hmac.c b/crypto/hmac/hmac.c index 31d08ef881..0eea5626e6 100644 --- a/crypto/hmac/hmac.c +++ b/crypto/hmac/hmac.c @@ -123,7 +123,8 @@ int HMAC_Init_ex(HMAC_CTX *ctx, const void *key, int len, &ctx->key_length)) goto err; } else { - OPENSSL_assert(len >= 0 && len <= (int)sizeof(ctx->key)); + if(len < 0 || len > (int)sizeof(ctx->key)) + return 0; memcpy(ctx->key, key, len); ctx->key_length = len; }