]> granicus.if.org Git - postgresql/commit
Fix generation of padding message before encrypting Elgamal in pgcrypto
authorMichael Paquier <michael@paquier.xyz>
Tue, 1 Jan 2019 01:39:19 +0000 (10:39 +0900)
committerMichael Paquier <michael@paquier.xyz>
Tue, 1 Jan 2019 01:39:19 +0000 (10:39 +0900)
commitd880b208e5fcf55e3ae396d5fc5fa6639f58205f
tree4607048daed196736ace80282789143e0c7535e3
parent8d3b389ec3405659d8e2968fc6179b28b286ccd8
Fix generation of padding message before encrypting Elgamal in pgcrypto

fe0a0b5, which has added a stronger random source in Postgres, has
introduced a thinko when creating a padding message which gets encrypted
for Elgamal.  The padding message cannot have zeros, which are replaced
by random bytes.  However if pg_strong_random() failed, the message
would finish by being considered in correct shape for encryption with
zeros.

Author: Tom Lane
Reviewed-by: Michael Paquier
Discussion: https://postgr.es/m/20186.1546188423@sss.pgh.pa.us
Backpatch-through: 10
contrib/pgcrypto/pgp-pubenc.c