From: Wolfgang Denk <wd@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH] cmd_sf: Fix problem with "sf update" and unaligned length
Date: Mon, 12 Jan 2015 22:10:34 +0100 [thread overview]
Message-ID: <20150112211034.AC27C384DF9@gemini.denx.de> (raw)
In-Reply-To: <54B37759.7040801@denx.de>
Dear Stefan,
In message <54B37759.7040801@denx.de> you wrote:
>
> > Should we add a memset(buf, 0, sizeof(buf)) before the memcpy() to
> > prevent information from earlier activities to leak?
>
> "buf" points to the new data to be written into the flash. We're
> overwriting the first "len" bytes of "cmp_buf" with this data.
Oh, sorry for the mixup. Then cmp_buf should be cleared (or at elast
the remaining, unused part).
> I don't see why we should erase anything there. Perhaps I'm missing
> something though.
You are leaking data. This could contain "interesting" information;
see the OpenSSL ?Heartbleed? vulnerability for a (nasty) example what
information leakage can do.
Best regards,
Wolfgang Denk
--
DENX Software Engineering GmbH, Managing Director: Wolfgang Denk
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: wd at denx.de
Very ugly or very beautiful women should be flattered on their
understanding, and mediocre ones on their beauty.
-- Philip Earl of Chesterfield
next prev parent reply other threads:[~2015-01-12 21:10 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-01-09 13:39 [U-Boot] [PATCH] cmd_sf: Fix problem with "sf update" and unaligned length Stefan Roese
2015-01-12 7:17 ` Wolfgang Denk
2015-01-12 7:27 ` Stefan Roese
2015-01-12 8:07 ` Gerlando Falauto
2015-01-12 21:12 ` Wolfgang Denk
2015-01-12 21:10 ` Wolfgang Denk [this message]
2015-01-13 6:05 ` Stefan Roese
2015-04-22 11:11 ` Jagan Teki
2015-04-22 11:15 ` Stefan Roese
2015-04-22 11:26 ` Jagan Teki
2015-01-12 7:51 ` Gerlando Falauto
2015-01-12 7:56 ` Stefan Roese
2015-01-12 8:12 ` Gerlando Falauto
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150112211034.AC27C384DF9@gemini.denx.de \
--to=wd@denx.de \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.