[PATCH gnupg] common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp.

Collin Funk collin.funk1 at gmail.com
Sat May 24 20:59:32 CEST 2025


Hi Werner,

Werner Koch <wk at gnupg.org> writes:

> Uiih, a classic brown paper bag bug for me.  Fortunately the code is
> only used by PKCS#15 cards as an early check for a proper public key.
>
> Thanks.  Will be applied soon.

Thanks! Yeah, I assumed from the test that it wasnt *too* important.

Collin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 832 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20250524/2d3f71c2/attachment.sig>


More information about the Gnupg-devel mailing list