Handle truncated message authentication codes.

This commit is contained in:
Guus Sliepen 2009-06-06 19:04:04 +02:00
parent 5a132550de
commit 4124b9682f
8 changed files with 64 additions and 49 deletions

View file

@ -163,7 +163,7 @@ static void receive_packet(node_t *n, vpn_packet_t *packet) {
static bool try_mac(node_t *n, const vpn_packet_t *inpkt)
{
if(!digest_active(&n->indigest) || !n->inmaclength || inpkt->len < sizeof inpkt->seqno + n->inmaclength)
if(!digest_active(&n->indigest) || inpkt->len < sizeof inpkt->seqno + digest_length(&n->indigest))
return false;
return digest_verify(&n->indigest, &inpkt->seqno, inpkt->len, &inpkt->seqno + inpkt->len);