FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

reject short sequence in cms content-type parsers by rootvector2 · Pull Request #2469 · bcgit/bc-java · GitHub

reject short sequence in cms content-type parsers - #2469

Closed
rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:cms-content-type-sequence-size
Closed

rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:cms-content-type-sequence-size

Conversation

Copy link
Copy Markdown
Contributor

the cms content-type decoders SignedData, EnvelopedData, AuthenticatedData, AuthEnvelopedData and EncryptedData read their mandatory fields with no lower-bound size check, so a ContentInfo whose inner content is an empty or too-short SEQUENCE leaks a NoSuchElementException/ArrayIndexOutOfBoundsException out of the throws CMSException contract of CMSSignedData(byte[]) and its siblings (the IllegalArgumentException CMSEncryptedData documents) — found auditing the CMS parse entry points; each now rejects a short sequence up front like CompressedData/DigestedData already do, covering the interspersed case where a leading OPTIONAL is claimed and the mandatory fields are then truncated.

AI tooling was used to help prepare this change.

dghgit commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Thanks for the PR. Merged with minor revisions. Now up on https://www.bouncycastle.org/betas

dghgit closed this Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL