• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
2  * All rights reserved.
3  *
4  * This package is an SSL implementation written
5  * by Eric Young (eay@cryptsoft.com).
6  * The implementation was written so as to conform with Netscapes SSL.
7  *
8  * This library is free for commercial and non-commercial use as long as
9  * the following conditions are aheared to.  The following conditions
10  * apply to all code found in this distribution, be it the RC4, RSA,
11  * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
12  * included with this distribution is covered by the same copyright terms
13  * except that the holder is Tim Hudson (tjh@cryptsoft.com).
14  *
15  * Copyright remains Eric Young's, and as such any Copyright notices in
16  * the code are not to be removed.
17  * If this package is used in a product, Eric Young should be given attribution
18  * as the author of the parts of the library used.
19  * This can be in the form of a textual message at program startup or
20  * in documentation (online or textual) provided with the package.
21  *
22  * Redistribution and use in source and binary forms, with or without
23  * modification, are permitted provided that the following conditions
24  * are met:
25  * 1. Redistributions of source code must retain the copyright
26  *    notice, this list of conditions and the following disclaimer.
27  * 2. Redistributions in binary form must reproduce the above copyright
28  *    notice, this list of conditions and the following disclaimer in the
29  *    documentation and/or other materials provided with the distribution.
30  * 3. All advertising materials mentioning features or use of this software
31  *    must display the following acknowledgement:
32  *    "This product includes cryptographic software written by
33  *     Eric Young (eay@cryptsoft.com)"
34  *    The word 'cryptographic' can be left out if the rouines from the library
35  *    being used are not cryptographic related :-).
36  * 4. If you include any Windows specific code (or a derivative thereof) from
37  *    the apps directory (application code) you must include an acknowledgement:
38  *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
39  *
40  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
41  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
42  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
43  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
44  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
45  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
46  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
48  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
49  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
50  * SUCH DAMAGE.
51  *
52  * The licence and distribution terms for any publically available version or
53  * derivative of this code cannot be changed.  i.e. this code cannot simply be
54  * copied and put under another distribution licence
55  * [including the GNU Public Licence.] */
56 
57 #include <openssl/asn1.h>
58 
59 #include <limits.h>
60 
61 #include <openssl/buf.h>
62 #include <openssl/err.h>
63 #include <openssl/mem.h>
64 
65 
66 static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb);
67 
68 #ifndef NO_OLD_ASN1
69 #ifndef OPENSSL_NO_FP_API
70 
ASN1_d2i_fp(void * (* xnew)(void),d2i_of_void * d2i,FILE * in,void ** x)71 void *ASN1_d2i_fp(void *(*xnew)(void), d2i_of_void *d2i, FILE *in, void **x)
72         {
73         BIO *b;
74         void *ret;
75 
76         if ((b=BIO_new(BIO_s_file())) == NULL)
77 		{
78 		OPENSSL_PUT_ERROR(ASN1, ERR_R_BUF_LIB);
79                 return(NULL);
80 		}
81         BIO_set_fp(b,in,BIO_NOCLOSE);
82         ret=ASN1_d2i_bio(xnew,d2i,b,x);
83         BIO_free(b);
84         return(ret);
85         }
86 #endif
87 
ASN1_d2i_bio(void * (* xnew)(void),d2i_of_void * d2i,BIO * in,void ** x)88 void *ASN1_d2i_bio(void *(*xnew)(void), d2i_of_void *d2i, BIO *in, void **x)
89 	{
90 	BUF_MEM *b = NULL;
91 	const unsigned char *p;
92 	void *ret=NULL;
93 	int len;
94 
95 	len = asn1_d2i_read_bio(in, &b);
96 	if(len < 0) goto err;
97 
98 	p=(unsigned char *)b->data;
99 	ret=d2i(x,&p,len);
100 err:
101 	if (b != NULL) BUF_MEM_free(b);
102 	return(ret);
103 	}
104 
105 #endif
106 
ASN1_item_d2i_bio(const ASN1_ITEM * it,BIO * in,void * x)107 void *ASN1_item_d2i_bio(const ASN1_ITEM *it, BIO *in, void *x)
108 	{
109 	BUF_MEM *b = NULL;
110 	const unsigned char *p;
111 	void *ret=NULL;
112 	int len;
113 
114 	len = asn1_d2i_read_bio(in, &b);
115 	if(len < 0) goto err;
116 
117 	p=(const unsigned char *)b->data;
118 	ret=ASN1_item_d2i(x,&p,len, it);
119 err:
120 	if (b != NULL) BUF_MEM_free(b);
121 	return(ret);
122 	}
123 
124 #ifndef OPENSSL_NO_FP_API
ASN1_item_d2i_fp(const ASN1_ITEM * it,FILE * in,void * x)125 void *ASN1_item_d2i_fp(const ASN1_ITEM *it, FILE *in, void *x)
126         {
127         BIO *b;
128         char *ret;
129 
130         if ((b=BIO_new(BIO_s_file())) == NULL)
131 		{
132 		OPENSSL_PUT_ERROR(ASN1, ERR_R_BUF_LIB);
133                 return(NULL);
134 		}
135         BIO_set_fp(b,in,BIO_NOCLOSE);
136         ret=ASN1_item_d2i_bio(it,b,x);
137         BIO_free(b);
138         return(ret);
139         }
140 #endif
141 
142 #define HEADER_SIZE   8
143 #define ASN1_CHUNK_INITIAL_SIZE (16 * 1024)
asn1_d2i_read_bio(BIO * in,BUF_MEM ** pb)144 static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
145 	{
146 	BUF_MEM *b;
147 	unsigned char *p;
148 	int i;
149 	ASN1_const_CTX c;
150 	size_t want=HEADER_SIZE;
151 	int eos=0;
152 	size_t off=0;
153 	size_t len=0;
154 
155 	b=BUF_MEM_new();
156 	if (b == NULL)
157 		{
158 		OPENSSL_PUT_ERROR(ASN1, ERR_R_MALLOC_FAILURE);
159 		return -1;
160 		}
161 
162 	ERR_clear_error();
163 	for (;;)
164 		{
165 		if (want >= (len-off))
166 			{
167 			want-=(len-off);
168 
169 			if (len + want < len || !BUF_MEM_grow_clean(b,len+want))
170 				{
171 				OPENSSL_PUT_ERROR(ASN1, ERR_R_MALLOC_FAILURE);
172 				goto err;
173 				}
174 			i=BIO_read(in,&(b->data[len]),want);
175 			if ((i < 0) && ((len-off) == 0))
176 				{
177 				OPENSSL_PUT_ERROR(ASN1, ASN1_R_NOT_ENOUGH_DATA);
178 				goto err;
179 				}
180 			if (i > 0)
181 				{
182 				if (len+i < len)
183 					{
184 					OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
185 					goto err;
186 					}
187 				len+=i;
188 				}
189 			}
190 		/* else data already loaded */
191 
192 		p=(unsigned char *)&(b->data[off]);
193 		c.p=p;
194 		c.inf=ASN1_get_object(&(c.p),&(c.slen),&(c.tag),&(c.xclass),
195 			len-off);
196 		if (c.inf & 0x80)
197 			{
198 			uint32_t e;
199 
200 			e=ERR_GET_REASON(ERR_peek_error());
201 			if (e != ASN1_R_TOO_LONG)
202 				goto err;
203 			else
204 				ERR_clear_error(); /* clear error */
205 			}
206 		i=c.p-p;/* header length */
207 		off+=i;	/* end of data */
208 
209 		if (c.inf & 1)
210 			{
211 			/* no data body so go round again */
212 			eos++;
213 			if (eos < 0)
214 				{
215 				OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
216 				goto err;
217 				}
218 			want=HEADER_SIZE;
219 			}
220 		else if (eos && (c.slen == 0) && (c.tag == V_ASN1_EOC))
221 			{
222 			/* eos value, so go back and read another header */
223 			eos--;
224 			if (eos <= 0)
225 				break;
226 			else
227 				want=HEADER_SIZE;
228 			}
229 		else
230 			{
231 			/* suck in c.slen bytes of data */
232 			want=c.slen;
233 			if (want > (len-off))
234 				{
235                                 size_t chunk_max = ASN1_CHUNK_INITIAL_SIZE;
236 				want-=(len-off);
237 				if (want > INT_MAX /* BIO_read takes an int length */ ||
238 					len+want < len)
239 						{
240 						OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
241 						goto err;
242 						}
243 				while (want > 0)
244 					{
245 
246                                         /*
247                                          * Read content in chunks of increasing size
248                                          * so we can return an error for EOF without
249                                          * having to allocate the entire content length
250                                          * in one go.
251                                          */
252                                         size_t chunk = want > chunk_max ? chunk_max : want;
253 
254                                         if (!BUF_MEM_grow_clean(b, len + chunk)) {
255                                           OPENSSL_PUT_ERROR(ASN1, ERR_R_MALLOC_FAILURE);
256                                           goto err;
257                                         }
258                                         want -= chunk;
259                                         while (chunk > 0) {
260                                           i = BIO_read(in, &(b->data[len]), chunk);
261                                           if (i <= 0) {
262                                             OPENSSL_PUT_ERROR(ASN1, ASN1_R_NOT_ENOUGH_DATA);
263                                             goto err;
264                                           }
265                                           /*
266                                            * This can't overflow because |len+want| didn't
267                                            * overflow.
268                                            */
269                                           len += i;
270                                           chunk -= i;
271                                         }
272                                         if (chunk_max < INT_MAX/2)
273                                           chunk_max *= 2;
274 					}
275 				}
276 			if (off + c.slen < off)
277 				{
278 				OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
279 				goto err;
280 				}
281 			off+=c.slen;
282 			if (eos <= 0)
283 				{
284 				break;
285 				}
286 			else
287 				want=HEADER_SIZE;
288 			}
289 		}
290 
291 	if (off > INT_MAX)
292 		{
293 		OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
294 		goto err;
295 		}
296 
297 	*pb = b;
298 	return off;
299 err:
300 	if (b != NULL) BUF_MEM_free(b);
301 	return -1;
302 	}
303