X-Git-Url: http://the.earth.li/gitweb/?a=blobdiff_plain;f=parsekey.c;h=d152166181577213b413a1e0463b76284b18a7d8;hb=b301aa6579da21bf9a8efeef0776b718f74480c5;hp=008248e005633f0563d9bdcd409c61130cfc1423;hpb=5d859953e393a2539e67df3ce73798e7029cf5b9;p=onak.git diff --git a/parsekey.c b/parsekey.c index 008248e..d152166 100644 --- a/parsekey.c +++ b/parsekey.c @@ -354,6 +354,41 @@ onak_status_t read_openpgp_stream(int (*getchar_func)(void *ctx, size_t count, } else { rc = ONAK_E_INVALID_PKT; } + if (rc == ONAK_E_OK) { + /* Make sure the packet version is sane */ + switch (curpacket->packet->tag) { + case OPENPGP_PACKET_ENCRYPTED_MDC: + /* These packets must be v1 */ + if (curpacket->packet->data[0] != 1) { + rc = ONAK_E_INVALID_PKT; + } + break; + case OPENPGP_PACKET_PKSESSIONKEY: + case OPENPGP_PACKET_ONEPASSSIG: + /* These packets must be v3 */ + if (curpacket->packet->data[0] != 3) { + rc = ONAK_E_INVALID_PKT; + } + break; + case OPENPGP_PACKET_SYMSESSIONKEY: + /* These packets must be v4 */ + if (curpacket->packet->data[0] != 4) { + rc = ONAK_E_INVALID_PKT; + } + break; + case OPENPGP_PACKET_SIGNATURE: + case OPENPGP_PACKET_SECRETKEY: + case OPENPGP_PACKET_PUBLICKEY: + /* Must be v2 -> v4 */ + if (curpacket->packet->data[0] < 2 || + curpacket->packet->data[0] > 4) { + rc = ONAK_E_INVALID_PKT; + } + break; + default: + break; + } + } } if (packetend != NULL) {