=================================================================== RCS file: /cvsrepo/anoncvs/cvs/src/usr.bin/ssh/ssh-rsa.c,v retrieving revision 1.31 retrieving revision 1.31.4.1 diff -u -r1.31 -r1.31.4.1 --- src/usr.bin/ssh/ssh-rsa.c 2003/11/10 16:23:41 1.31 +++ src/usr.bin/ssh/ssh-rsa.c 2005/09/02 03:45:01 1.31.4.1 @@ -14,7 +14,7 @@ * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ #include "includes.h" -RCSID("$OpenBSD: ssh-rsa.c,v 1.31 2003/11/10 16:23:41 jakob Exp $"); +RCSID("$OpenBSD: ssh-rsa.c,v 1.31.4.1 2005/09/02 03:45:01 brad Exp $"); #include #include @@ -238,7 +238,7 @@ ERR_error_string(ERR_get_error(), NULL)); goto done; } - if (len != hlen + oidlen) { + if (len < 0 || (u_int)len != hlen + oidlen) { error("bad decrypted len: %d != %d + %d", len, hlen, oidlen); goto done; }