Skip to content

GCM tag() can return an unwritten tag; RSA decrypt2 accepts a wrong-length plaintext #91

Description

@MarkAtwood
  • GCM: after a one-shot gnutls_aead_cipher_decrypt, a decryptv2 on the same handle with empty ciphertext, attacker-chosen AAD and a zero tag is accepted (nettle rejects it). encryptv can emit stale buffer bytes as the tag. TLS is not affected.
  • RSA: gnutls_privkey_decrypt_data2 returns success for a plaintext shorter than requested (nettle returns an error).

Fixes and tests: #88 (closed in favour of this issue).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions