| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Thanks for the PR. Merged with minor revisions. Now up on https://www.bouncycastle.org/betas |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
the cms content-type decoders SignedData, EnvelopedData, AuthenticatedData, AuthEnvelopedData and EncryptedData read their mandatory fields with no lower-bound size check, so a ContentInfo whose inner content is an empty or too-short SEQUENCE leaks a NoSuchElementException/ArrayIndexOutOfBoundsException out of the throws CMSException contract of CMSSignedData(byte[]) and its siblings (the IllegalArgumentException CMSEncryptedData documents) — found auditing the CMS parse entry points; each now rejects a short sequence up front like CompressedData/DigestedData already do, covering the interspersed case where a leading OPTIONAL is claimed and the mandatory fields are then truncated.
AI tooling was used to help prepare this change.