Bugs item #3603901, was opened at 2013-02-08 18:37
Message generated for change (Settings changed) made by danielel
You can respond by visiting: 

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: None
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: https://www.google.com/accounts ()
>Assigned to: Daniele Lacamera (danielel)
Summary: incorrect crc32 comparisons

Initial Comment:
Hello, while performing an audit of vde2 
(https://bugs.launchpad.net/ubuntu/+source/vde2/+bug/776818) I found a bug.

cryptcab decided to treat crc32 values as a string for some reason. In doing 
so, it incorrectly compares two crc32 values:

isvalid_crc32(unsigned char *block, int len)
        unsigned char *crc=(unsigned char *)crc32(block,len-4);
                return 1;

                //fprintf(stderr,"bad crc32!\n");
                return 0;

strcmp will stop reading at the first 0x00 character ('\0') in the string, 
whether it is intentional or not. Further characters are not compared.

If the string implementation is desirable, then this code should switch to 
memcmp(3), and a specified length of '4'.

However, this entire string-based comparison could probably be replaced if the 
crc32() were redesigned to use htonl(3) to manipulate the crc32 values as a 
single four-byte entity. These can be compared using == directly and without 
invoking malloc(3) and free(3). However, I have not tested that htonl(3) is an 
accurate replacement, so please be sure to test this thoroughly. (The existing 
code may actually be incorrect on PowerPC, SPARC, MIPS, etc. I also haven't 
tested this guess.)


You can respond by visiting: 

Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester  
Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the  
endpoint security space. For insight on selecting the right partner to 
tackle endpoint security challenges, access the full report. 
vde-users mailing list

Reply via email to