As we do a sscanf() on the buffer. Noted by valgrind.
int para_decrypt_challenge(char *key_file, long unsigned *challenge_nr,
unsigned char *inbuf, int rsa_inlen)
{
- unsigned char *rsa_out = OPENSSL_malloc(128);
+ unsigned char *rsa_out = OPENSSL_malloc(rsa_inlen + 1);
int ret = para_decrypt_buffer(key_file, rsa_out, inbuf, rsa_inlen);
- if (ret >= 0)
+ if (ret >= 0) {
+ rsa_out[ret] = '\0';
ret = sscanf((char *)rsa_out, "%lu", challenge_nr) == 1?
1 : -E_CHALLENGE;
+ }
OPENSSL_free(rsa_out);
return ret;
}