Found by tis-interpreter
Reviewed-by: Rich Salz <rsalz@openssl.org>
GH: #1179
if (ret == NULL)
return (NULL);
bn_check_top(ret);
- s += len - 1;
+ s += len;
/* Skip trailing zeroes. */
- for ( ; len > 0 && *s == 0; s--, len--)
+ for ( ; len > 0 && s[-1] == 0; s--, len--)
continue;
n = len;
if (n == 0) {
ret->neg = 0;
l = 0;
while (n--) {
- l = (l << 8L) | *(s--);
+ s--;
+ l = (l << 8L) | *s;
if (m-- == 0) {
ret->d[--i] = l;
l = 0;
/* Add trailing zeroes if necessary */
if (tolen > i)
memset(to + i, 0, tolen - i);
- to += i - 1;
+ to += i;
while (i--) {
l = a->d[i / BN_BYTES];
- *(to--) = (unsigned char)(l >> (8 * (i % BN_BYTES))) & 0xff;
+ to--;
+ *to = (unsigned char)(l >> (8 * (i % BN_BYTES))) & 0xff;
}
return tolen;
}