diff --git a/[refs] b/[refs] index 4851311e1e18..07f655a9aa1f 100644 --- a/[refs] +++ b/[refs] @@ -1,2 +1,2 @@ --- -refs/heads/master: 8507876aaada8a2cf68ebccdf1d056465dd1fc11 +refs/heads/master: bc01637a80f5b670bd70a0279d3f93fa8de1c96d diff --git a/trunk/lib/digsig.c b/trunk/lib/digsig.c index 286d558033e2..8c0e62975c88 100644 --- a/trunk/lib/digsig.c +++ b/trunk/lib/digsig.c @@ -163,9 +163,11 @@ static int digsig_verify_rsa(struct key *key, memcpy(out1 + head, p, l); err = pkcs_1_v1_5_decode_emsa(out1, len, mblen, out2, &len); + if (err) + goto err; - if (!err && len == hlen) - err = memcmp(out2, h, hlen); + if (len != hlen || memcmp(out2, h, hlen)) + err = -EINVAL; err: mpi_free(in);