diff options
author | Allan McRae <allan@archlinux.org> | 2020-05-20 06:17:11 +0200 |
---|---|---|
committer | Allan McRae <allan@archlinux.org> | 2020-06-01 02:59:08 +0200 |
commit | 5f6ef895b1dac04c7fb1b63acab2d42c19f91922 (patch) | |
tree | 8396813a300f02df7f41a66c0b88d523dac6dc40 /lib | |
parent | 23b50d60e34e324cf6f420c05293f7fa8a909623 (diff) | |
download | pacman-5f6ef895b1dac04c7fb1b63acab2d42c19f91922.tar.gz pacman-5f6ef895b1dac04c7fb1b63acab2d42c19f91922.tar.xz |
libalpm/signing.c: Fix calculation of packet size in parse_subpacket
Given RFC 4880 provides the code to do this calculation, I am not sure
how I managed to stuff that up! This bug was only exposed when a
signature made with "include-key-block" was added to the Arch repos,
which provided a subpacket with the required size to hit this issue.
Signed-off-by: Allan McRae <allan@archlinux.org>
Diffstat (limited to 'lib')
-rw-r--r-- | lib/libalpm/signing.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/libalpm/signing.c b/lib/libalpm/signing.c index c8eaaca2..2cbbd103 100644 --- a/lib/libalpm/signing.c +++ b/lib/libalpm/signing.c @@ -1058,7 +1058,7 @@ static int parse_subpacket(alpm_handle_t *handle, const char *identifier, if(length_check(len, spos, 2, handle, identifier) != 0){ return -1; } - slen = (sig[spos] << 8) | sig[spos + 1]; + slen = ((sig[spos] - 192) << 8) + sig[spos + 1] + 192; spos = spos + 2; } else { if(length_check(len, spos, 5, handle, identifier) != 0) { |