Skip to content

Commit b5b5a5b

Browse files
committed
8336667: IAE in DerInputStream.toByteArray
Reviewed-by: valeriep
1 parent cf0d9e0 commit b5b5a5b

File tree

3 files changed

+113
-2
lines changed

3 files changed

+113
-2
lines changed

src/java.base/share/classes/sun/security/util/DerInputStream.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright (c) 1996, 2023, Oracle and/or its affiliates. All rights reserved.
2+
* Copyright (c) 1996, 2024, Oracle and/or its affiliates. All rights reserved.
33
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
44
*
55
* This code is free software; you can redistribute it and/or modify it
@@ -114,7 +114,7 @@ public DerValue getDerValue() throws IOException {
114114
// to the end of return value by DerIndefLenConverter::convertBytes
115115
// and stay inside result.buffer.
116116
int unused = result.buffer.length - result.end;
117-
this.pos = this.data.length - unused;
117+
this.pos = this.end - unused;
118118
} else {
119119
this.pos = result.end;
120120
}
Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
/*
2+
* Copyright (c) 2024, Oracle and/or its affiliates. All rights reserved.
3+
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4+
*
5+
* This code is free software; you can redistribute it and/or modify it
6+
* under the terms of the GNU General Public License version 2 only, as
7+
* published by the Free Software Foundation.
8+
*
9+
* This code is distributed in the hope that it will be useful, but WITHOUT
10+
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11+
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12+
* version 2 for more details (a copy is included in the LICENSE file that
13+
* accompanied this code).
14+
*
15+
* You should have received a copy of the GNU General Public License version
16+
* 2 along with this work; if not, write to the Free Software Foundation,
17+
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
18+
*
19+
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
20+
* or visit www.oracle.com if you need additional information or have any
21+
* questions.
22+
*/
23+
24+
/*
25+
* @test
26+
* @bug 8336667
27+
* @summary Ensure the unused bytes are calculated correctly when converting
28+
* indefinite length BER to DER
29+
* @modules java.base/sun.security.util
30+
* @library /test/lib
31+
*/
32+
import jdk.test.lib.Asserts;
33+
import sun.security.util.DerInputStream;
34+
35+
import java.util.HexFormat;
36+
37+
public class PoC {
38+
public static void main(String[] args) throws Exception {
39+
// A BER indefinite encoding with some unused bytes at the end
40+
var data = HexFormat.of().parseHex("""
41+
2480 0401AA 0401BB 0000 -- 2 byte string
42+
010100 -- boolean false
43+
12345678 -- 4 unused bytes"""
44+
.replaceAll("(\\s|--.*)", ""));
45+
var dis = new DerInputStream(data, 0, data.length - 4, true);
46+
Asserts.assertEQ(dis.getDerValue().getOctetString().length, 2);
47+
Asserts.assertFalse(dis.getDerValue().getBoolean());
48+
dis.atEnd();
49+
}
50+
}
Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
/*
2+
* Copyright (c) 2024, Oracle and/or its affiliates. All rights reserved.
3+
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4+
*
5+
* This code is free software; you can redistribute it and/or modify it
6+
* under the terms of the GNU General Public License version 2 only, as
7+
* published by the Free Software Foundation.
8+
*
9+
* This code is distributed in the hope that it will be useful, but WITHOUT
10+
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11+
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12+
* version 2 for more details (a copy is included in the LICENSE file that
13+
* accompanied this code).
14+
*
15+
* You should have received a copy of the GNU General Public License version
16+
* 2 along with this work; if not, write to the Free Software Foundation,
17+
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
18+
*
19+
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
20+
* or visit www.oracle.com if you need additional information or have any
21+
* questions.
22+
*/
23+
24+
/*
25+
* @test
26+
* @bug 8336667
27+
* @summary Ensure the unused bytes are calculated correctly when converting
28+
* indefinite length BER to DER
29+
*/
30+
import java.io.ByteArrayInputStream;
31+
import java.security.cert.CRLException;
32+
import java.security.cert.CertificateException;
33+
import java.util.Base64;
34+
35+
public class Reproducer {
36+
private static final String INPUT = """
37+
MIIBljCCAVMwgAaB/////////yb////////////////////9////AgDv////////////////////
38+
/////2RjPWNvbf////8k/////////yb///////////////////9vbf////8k/////////yb/////
39+
////////////////////AgD/////////////b23/////JP////////8m/////yf/////////////
40+
/////wIA//////////////////////////////////////8AAABl//////8m/////////y1CRUdJ
41+
TiA9Y290cnVlVlZWVlZWVlZWVjEAAAAAAAAArQdVUwNVBAsTA0RvRDEaMBhAA1UAAAAAAAAAAAAA
42+
AAAAAAAAAAAAAAAAAAEXDTAzMDcxNTE2MjAwNFqgHzAdMA8GA1UdHAEB/wQFMAPyAf8wCgYDVR0P
43+
BAMCAQIwCwYHKoZIzjgEAwUAAzBkARkTA2NvbTEYMBYGCgmSJomT8ixkARkTCG15VGVzdENBMBIC
44+
AQHyAjZG+RfHdO4=""";
45+
46+
Reproducer(byte[] data) {
47+
try {
48+
java.security.cert.CertificateFactory.
49+
getInstance("X.509").generateCRLs(new ByteArrayInputStream(data));
50+
} catch (CertificateException | CRLException e) {
51+
if (System.getProperty("dbg", "false").equals("true")) {
52+
e.printStackTrace();
53+
}
54+
}
55+
}
56+
57+
public static void main(String[] a) throws Exception {
58+
byte[] decodedBytes = Base64.getMimeDecoder().decode(INPUT);
59+
new Reproducer(decodedBytes);
60+
}
61+
}

0 commit comments

Comments
 (0)