Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8217344

Make comparison overflow-aware in ECDHKeyAgreement.engineGenerateSecret()

    Details

    • Subcomponent:
    • Resolved In Build:
      b05
    • Verification:
      Not verified

      Backports

        Description

        This is analogous to what was done in XDHKeyAgreement::engineGenerateSecret via JDK-8201317.

        - if (offset + secretLen > sharedSecret.length) {
        + if (secretLen > sharedSecret.length - offset) {

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  igerasim Ivan Gerasimov
                  Reporter:
                  igerasim Ivan Gerasimov
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  3 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved: