CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/09/12 01:03:00
Modified files:
usr.sbin/rpki-client: validate.c
Log message:
rpki-client: fix valid_uri() to work with non-strings
valid_uri() takes a length parameter and should honor that. Most uris
passed are NUL terminated, but the ones coming from an ASN1_STRING are
not guaranteed to be. Calling strstr() on a non-terminated string with
no match is a buffer overread. So use memmem() instead.
This is needed for rpki-client to work with OpenSSL 4.1, who, in their
infinite disregard for downstreams chose to stop NUL-terminating ASN.1
strings. A massive breaking change in a minor release that will surely
cause lots of buffer overreads. It's also not mentioned in CHANGES.md,
only in their terrible migration guide. Of course it's been documented
since forever, but who reads OpenSSL's crappy documentation anyway?
ok claudio