From 64b8fc71b5fd9db4364842cf674b1824cbb42f7d Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 3 Apr 2020 16:25:12 -0400 Subject: [PATCH] Handle DER with trailer field in PSS parameters Signed-off-by: Alexander Scheel --- .../jss/provider/java/security/RSAPSSAlgorithmParameters.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/org/mozilla/jss/provider/java/security/RSAPSSAlgorithmParameters.java b/org/mozilla/jss/provider/java/security/RSAPSSAlgorithmParameters.java index 1c556bc07..1c6438996 100644 --- a/org/mozilla/jss/provider/java/security/RSAPSSAlgorithmParameters.java +++ b/org/mozilla/jss/provider/java/security/RSAPSSAlgorithmParameters.java @@ -124,7 +124,7 @@ private void decode(DerInputStream in , byte[] encoded) throws IOException { // Sequence has 3 members, trailer field ignored DerValue seq[] = in.getSequence(3); - if(seq.length != 3) { + if(seq.length < 3 || seq.length > 4) { throw new IOException("Invalid data!"); }