diff options
| author | Matthew Garrett <mjg@redhat.com> | 2012-07-09 10:17:13 -0400 |
|---|---|---|
| committer | Matthew Garrett <mjg@redhat.com> | 2012-07-09 10:17:13 -0400 |
| commit | 5f64876076e6d60f4cabc62892a2d857d6e3b02f (patch) | |
| tree | b0b869509559f28f9d0c6c914cbc3e7ec65fe28f /Cryptlib/Pk/CryptAuthenticode.c | |
| parent | b2058cf8973ce8b0e98437293ac54f88decaf48a (diff) | |
| download | efi-boot-shim-5f64876076e6d60f4cabc62892a2d857d6e3b02f.tar.gz efi-boot-shim-5f64876076e6d60f4cabc62892a2d857d6e3b02f.zip | |
Cryptlib update
Diffstat (limited to 'Cryptlib/Pk/CryptAuthenticode.c')
| -rw-r--r-- | Cryptlib/Pk/CryptAuthenticode.c | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/Cryptlib/Pk/CryptAuthenticode.c b/Cryptlib/Pk/CryptAuthenticode.c index a1f8c58e..a4f62b22 100644 --- a/Cryptlib/Pk/CryptAuthenticode.c +++ b/Cryptlib/Pk/CryptAuthenticode.c @@ -1,6 +1,14 @@ /** @file
Authenticode Portable Executable Signature Verification over OpenSSL.
+ Caution: This module requires additional review when modified.
+ This library will have external input - signature (e.g. PE/COFF Authenticode).
+ This external input must be validated carefully to avoid security issue like
+ buffer overflow, integer overflow.
+
+ AuthenticodeVerify() will get PE/COFF Authenticode and will do basic check for
+ data structure.
+
Copyright (c) 2011 - 2012, Intel Corporation. All rights reserved.<BR>
This program and the accompanying materials
are licensed and made available under the terms and conditions of the BSD License
@@ -26,6 +34,10 @@ WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED. If AuthData is NULL, then return FALSE.
If ImageHash is NULL, then return FALSE.
+ Caution: This function may receive untrusted input.
+ PE/COFF Authenticode is external input, so this function will do basic check for
+ Authenticode data structure.
+
@param[in] AuthData Pointer to the Authenticode Signature retrieved from signed
PE/COFF image to be verified.
@param[in] DataSize Size of the Authenticode Signature in bytes.
|
