From c62e94d805fa2900a0d6d723715aaf45f75b6c14 Mon Sep 17 00:00:00 2001 From: Matt Caswell Date: Tue, 10 Feb 2015 13:15:25 +0000 Subject: [PATCH] Fix HMAC to pass invalid key len test Reviewed-by: Richard Levitte --- crypto/hmac/hmac.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/crypto/hmac/hmac.c b/crypto/hmac/hmac.c index f1fdba42d8..8ee5b2ac19 100644 --- a/crypto/hmac/hmac.c +++ b/crypto/hmac/hmac.c @@ -93,7 +93,8 @@ int HMAC_Init_ex(HMAC_CTX *ctx, const void *key, int len, &ctx->key_length)) goto err; } else { - OPENSSL_assert(len >= 0 && len <= (int)sizeof(ctx->key)); + if(len < 0 || len > (int)sizeof(ctx->key)) + return 0; memcpy(ctx->key, key, len); ctx->key_length = len; } -- 2.40.0