Re: BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0 - Mailing list pgsql-bugs

From shihao zhong
Subject Re: BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0
Date
Msg-id CAGRkXqR5G=Z1U5-EE_LGqa9TGP082sJiBZM4JR39crbrzVZbXw@mail.gmail.com
Whole thread
In response to BUG #19714: pgcrypto pgp_sym_encrypt accepts nonnumeric s2k-mode as mode 0  (PG Bug reporting form <noreply@postgresql.org>)
List pgsql-bugs
Hi

All the integer PGP options are parsed with atoi(), so trailing junk
("s2k-mode=3x") and values that wrap around int ("s2k-mode=4294967299"
gives 3) get through too.

This is not a common case. It only happens when the caller writes a bad
option string, and the caller could ask for mode 0 directly anyway, so
it is not a security problem. The one case worth fixing is s2k-mode.
Junk there gives the unsalted mode 0, and decryption still works, so
nobody would notice. "s2k-mode=salted" is an easy mistake to make,
since the other S2K options take names.

0001 parses the values with strtoint() and raises the existing "Illegal
argument to function" error. 0002 adds tests and is optional.

This makes some inputs that work today fail, so I'd keep it to master.
I can do back-branch versions if a committer wants it back-patched.

Shihao
Attachment

pgsql-bugs by date:

Previous
From: shihao zhong
Date:
Subject: Re: BUG #19705: One NaN box makes a BRIN box_inclusion_ops index omit unrelated rows
Next
From: PG Bug reporting form
Date:
Subject: BUG #19719: BUG: huge_pages=on shared memory reattached without FILE_MAP_LARGE_PAGES on Windows