Commit Detail
Commit ddd54a6
Validate DH public keys proactively in setPublicKey and computeSecret `DiffieHellman::setPublicKey()` accepted arbitrary byte arrays without validation, allowing keys of 0, 1, or values >= p that would cause `computeSecret()` to produce predictable or weak shared secrets. `computeSecret()` only called `DH_check_pub_key` on the error path after `DH_compute_key` had already failed. Add `DH_check_pub_key` validation in both `setPublicKey()` (rejects invalid keys at the point they're set) and `computeSecret()` (rejects invalid peer keys before computing the shared secret, not after). This catches small subgroup attacks and out-of-range keys with clear error messages.
Files changed
2 files changed~2 modified