[tor-bugs] #13538 [Tor]: Stop signed left shift overflows in curve25519-donna (non-64-bit)

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Jan 3 06:45:28 UTC 2016


#13538: Stop signed left shift overflows in curve25519-donna (non-64-bit)
---------------------------------------------+-----------------------------
 Reporter:  teor                             |          Owner:
     Type:  defect                           |         Status:  assigned
 Priority:  Medium                           |      Milestone:  Tor:
Component:  Tor                              |  0.2.???
 Severity:  Normal                           |        Version:  Tor:
 Keywords:  tor-router integer-safety lorax  |  unspecified
Parent ID:                                   |     Resolution:
  Sponsor:                                   |  Actual Points:
                                             |         Points:
---------------------------------------------+-----------------------------
Changes (by teor):

 * keywords:  tor-router integer-safety => tor-router integer-safety lorax
 * owner:  teor =>
 * severity:   => Normal


Comment:

 Building curve-25519 with -fwrapv would also resolve this issue.
 If it becomes an issue with some compiler, let's resolve it that way.

 (Note that --enable-gcc-hardening adds -fwrapv to CFLAGS, but it's not on
 by default.)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13538#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list