[tor-bugs] #22746 [Core Tor/Tor]: CID 1413651: No retval check in ed25519_donna_blind_public_key()
Tor Bug Tracker & Wiki
blackhole at torproject.org
Wed Jun 28 12:48:33 UTC 2017
#22746: CID 1413651: No retval check in ed25519_donna_blind_public_key()
--------------------------+------------------------------------
Reporter: asn | Owner:
Type: defect | Status: needs_revision
Priority: Medium | Milestone: Tor: 0.3.2.x-final
Component: Core Tor/Tor | Version:
Severity: Normal | Resolution:
Keywords: coverity | Actual Points:
Parent ID: | Points: 0.1
Reviewer: | Sponsor: SponsorR-can
--------------------------+------------------------------------
Changes (by asn):
* status: needs_review => needs_revision
Comment:
No these new error paths are not tested. I think we need to provide a
pubkey value that is not on the curve to the blinding function to make
them fail. I'll try to do this.
And now that you mention it, I guess this needs a changes file as well,
since the "bug" is on the blinding functions and not on the unreleased
#22006 code (but I guess the retval checking of the #22006 code inspired
coverity to find this bug).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22746#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list