| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Thanks for the PR. Merged with minor revisions. Now up on https://www.bouncycastle.org/betas |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
OCSPResp(byte[]) and OCSPReq(byte[]) only catch IllegalArgumentException, ClassCastException and ASN1Exception around the decode, so a top-level SEQUENCE that is empty or truncated makes OCSPResponse/OCSPRequest read seq.getObjectAt(0) out of bounds and the ArrayIndexOutOfBoundsException escapes the declared throws IOException (an OCSP client parsing a response, or a responder parsing a request, crashes instead of rejecting the input). Both now surface any RuntimeException from the decode as CertIOException, matching what X509CertificateHolder.parseBytes and X509CRLHolder.parseStream already do. Found while checking the cert byte[] parse entry points for the RuntimeException guard those two classes carry; new OCSPResp(new byte[]{0x30, 0x00}) reproduces it, and the added OCSPMalformedInputTest covers empty/truncated/non-SEQUENCE encodings for both parsers plus a valid request/response round trip.
AI tooling was used to help prepare this change.