From bc3bf85dd0031681ba872a4fac135a51e68684c8 Mon Sep 17 00:00:00 2001 From: doug Date: Sat, 20 Jun 2015 01:21:51 +0000 Subject: [PATCH] Replace internal call to CRYPTO_memcmp with timingsafe_memcmp. Suggested by jsing@. ok jsing@ miod@ --- lib/libssl/bs_cbs.c | 4 ++-- lib/libssl/src/ssl/bs_cbs.c | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/lib/libssl/bs_cbs.c b/lib/libssl/bs_cbs.c index 81731772496..ea31cfc5300 100644 --- a/lib/libssl/bs_cbs.c +++ b/lib/libssl/bs_cbs.c @@ -1,4 +1,4 @@ -/* $OpenBSD: bs_cbs.c,v 1.14 2015/06/19 00:23:36 doug Exp $ */ +/* $OpenBSD: bs_cbs.c,v 1.15 2015/06/20 01:21:51 doug Exp $ */ /* * Copyright (c) 2014, Google Inc. * @@ -127,7 +127,7 @@ CBS_mem_equal(const CBS *cbs, const uint8_t *data, size_t len) if (len != cbs->len) return 0; - return CRYPTO_memcmp(cbs->data, data, len) == 0; + return timingsafe_memcmp(cbs->data, data, len) == 0; } static int diff --git a/lib/libssl/src/ssl/bs_cbs.c b/lib/libssl/src/ssl/bs_cbs.c index 81731772496..ea31cfc5300 100644 --- a/lib/libssl/src/ssl/bs_cbs.c +++ b/lib/libssl/src/ssl/bs_cbs.c @@ -1,4 +1,4 @@ -/* $OpenBSD: bs_cbs.c,v 1.14 2015/06/19 00:23:36 doug Exp $ */ +/* $OpenBSD: bs_cbs.c,v 1.15 2015/06/20 01:21:51 doug Exp $ */ /* * Copyright (c) 2014, Google Inc. * @@ -127,7 +127,7 @@ CBS_mem_equal(const CBS *cbs, const uint8_t *data, size_t len) if (len != cbs->len) return 0; - return CRYPTO_memcmp(cbs->data, data, len) == 0; + return timingsafe_memcmp(cbs->data, data, len) == 0; } static int -- 2.20.1