[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #22746 [Core Tor/Tor]: CID 1413651: No retval check in ed25519_donna_blind_public_key()



#22746: CID 1413651:  No retval check in ed25519_donna_blind_public_key()
--------------------------+------------------------------------
 Reporter:  asn           |          Owner:
     Type:  defect        |         Status:  needs_revision
 Priority:  Medium        |      Milestone:  Tor: 0.3.2.x-final
Component:  Core Tor/Tor  |        Version:
 Severity:  Normal        |     Resolution:
 Keywords:  coverity      |  Actual Points:
Parent ID:                |         Points:  0.1
 Reviewer:                |        Sponsor:  SponsorR-can
--------------------------+------------------------------------
Changes (by asn):

 * status:  needs_review => needs_revision


Comment:

 No these new error paths are not tested. I think we need to provide a
 pubkey value that is not on the curve to the blinding function to make
 them fail. I'll try to do this.

 And now that you mention it, I guess this needs a changes file as well,
 since the "bug" is on the blinding functions and not on the unreleased
 #22006 code (but I guess the retval checking of the #22006 code inspired
 coverity to find this bug).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22746#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs