Browse code

Check return value of ms_error_text()

ms_error_text() may return NULL, and it is unclear (or, at least
undocumented) whether the OpenSSL ERR code (and our code using the ERR
code) can deal with esd->string being NULL. So, just to be sure, check
that ms_error_text() succeeded before passing the result to
ERR_load_strings().

Signed-off-by: Steffan Karger <steffan@karger.me>
Acked-by: Gert Doering <gert@greenie.muc.de>
Message-Id: <561130FC.8090008@karger.me>
URL: http://article.gmane.org/gmane.network.openvpn.devel/10176
Signed-off-by: Gert Doering <gert@greenie.muc.de>

Steffan Karger authored on 2015/09/22 05:04:19
Showing 1 changed files
... ...
@@ -164,6 +164,7 @@ static void err_put_ms_error(DWORD ms_err, int func, const char *file, int line)
164 164
 	    err_map[i].ms_err = ms_err;
165 165
 	    err_map[i].err = esd->error = i + 100;
166 166
 	    esd->string = ms_error_text(ms_err);
167
+	    check_malloc_return(esd->string);
167 168
 	    ERR_load_strings(ERR_LIB_CRYPTOAPI, esd);
168 169
 	    ERR_PUT_error(ERR_LIB_CRYPTOAPI, func, err_map[i].err, file, line);
169 170
 	    break;