mbedtls/include/polarssl
Paul Bakker 956c9e063d Reduced the input / output overhead with 200+ bytes and covered corner
case

The actual input / output buffer overhead is only 301 instead of 512.
This requires a proper check on the padding_idx to prevent out of bounds
reads.

Previously a remote party could potentially trigger an access error and
thus stop the application when sending a malicious packet having
MAX_CONTENT_LEN of data, 32 bytes of MAC and a decrypted padlen of .
This would result in reading from in_ctr + 13 + 32 + MAX_CONTENT_LEN - 1 - 1
for 256 bytes (including fake padding check). Or 13 + 32 bytes over the
buffer length.

We now reset padding_idx to 0, if it's clear that it will never be a
valid padding (padlen > msg_len || msg_len + padlen + 256 > buffer_len)
2013-12-30 15:00:51 +01:00
..
aes.h Add AES-NI key expansion for 256 bits 2013-12-29 13:50:32 +01:00
aesni.h aesni_gcm_mult() now returns void 2013-12-30 13:54:23 +01:00
arc4.h
asn1.h Fixed doxygen documentation in asn1.h (added \brief) 2013-09-09 12:51:29 +02:00
asn1write.h Adapt asn1_write_algorithm_identifier() to params 2013-09-12 11:57:01 +02:00
base64.h
bignum.h Allow to test 32-bit ints more easily 2013-12-17 11:27:20 +01:00
blowfish.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
bn_mul.h
camellia.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
certs.h Simplify the way default certs are used 2013-09-25 14:05:49 +02:00
cipher_wrap.h Refactor cipher information management 2013-09-18 15:37:44 +02:00
cipher.h cipher layer: IV length is not always block size 2013-10-24 17:17:54 +02:00
compat-1.2.h compat-1.2.h: Make inline functions static 2013-11-20 16:13:13 +01:00
config.h Add files for (upcoming) AES-NI support 2013-12-25 13:03:26 +01:00
ctr_drbg.h Updated doxygen documentation in header files and HTML pages 2013-09-10 16:16:50 +02:00
debug.h Renamed x509_cert structure to x509_crt for consistency 2013-09-18 14:32:52 +02:00
des.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
dhm.h Possible naming collision in dhm_context 2013-10-11 09:38:49 +02:00
ecdh.h Add ecdh_get_params() to import from an EC key 2013-12-17 11:32:31 +01:00
ecdsa.h Remove polarssl/ from header includes 2013-10-11 09:17:09 +02:00
ecp.h Adapt ecp_group_free() to static constants 2013-12-17 11:27:20 +01:00
entropy_poll.h
entropy.h entropy_func() threading support 2013-09-29 15:02:07 +02:00
error.h Fix bad error codes 2013-10-27 13:48:15 +01:00
gcm.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
havege.h
md2.h
md4.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
md5.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
md_wrap.h
md.h Made POLARSSL_MD_MAX_SIZE dependent on POLARSSL_SHA512_C 2013-09-10 11:10:57 +02:00
memory.h Buffer allocator threading support 2013-09-29 15:02:11 +02:00
net.h Adapt net_accept() to IPv6 2013-12-17 12:00:57 +01:00
oid.h Support for serialNumber, postalAddress and postalCode in X509 names 2013-10-29 14:24:37 +01:00
openssl.h Fixed cplusplus extern defines in header files 2013-10-01 10:09:06 +02:00
padlock.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
pbkdf2.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
pem.h POLARSSL_PEM_C split into POLARSSL_PEM_PARSE_C and POLARSSL_PEM_WRITE_C 2013-09-16 13:36:18 +02:00
pk_wrap.h
pk.h Fix pkcs11.c to conform to PolarSSL 1.3 API. 2013-11-20 16:13:27 +01:00
pkcs5.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
pkcs11.h Fix pkcs11.c to conform to PolarSSL 1.3 API. 2013-11-20 16:13:27 +01:00
pkcs12.h
rsa.h RSA blinding threading support 2013-09-29 15:02:11 +02:00
sha1.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
sha256.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00
sha512.h
ssl_cache.h SSL Cache threading support 2013-09-28 15:24:59 +02:00
ssl_ciphersuites.h Fix bug in ciphersuite number 2013-12-17 11:32:31 +01:00
ssl.h Reduced the input / output overhead with 200+ bytes and covered corner 2013-12-30 15:00:51 +01:00
threading.h Clarified threading issues 2013-09-30 15:24:33 +02:00
timing.h
version.h Prep for PolarSSL 1.3.2 2013-11-04 17:29:42 +01:00
x509_crl.h Renamed x509parse_* functions to new form 2013-09-18 13:46:23 +02:00
x509_crt.h Document x509_crt_parse_path() threading behaviour 2013-11-28 18:07:39 +01:00
x509_csr.h Const correctness 2013-10-28 21:19:10 +01:00
x509.h Const correctness 2013-10-28 21:19:10 +01:00
xtea.h Defines for UEFI environment under MSVC added 2013-10-29 14:05:38 +01:00