px5g return value checking

Peter Naulls peter at chocky.org
Thu Nov 3 11:49:06 PDT 2022


Another one from our security scan:

File: /usr/sbin/px5g
Issue: RET NOT ASSIGNED in function 'FUN_000281b0' at address 0x281c0 while 
calling 'mbedtls_rsa_check_pub_priv'
Issue: RET NOT ASSIGNED in function 'FUN_000285e8' at address 0x285f8 while 
calling 'mbedtls_ecp_check_pub_priv'

I'm not familiar with this code, and looking I can't see anything obvious.
I do note that the function "rsa_check_pair_wrap" is used as a function
pointer, which might be upsetting scans.

This is mbedtls-2.28.1.

Can someone verify this or see if it's a false positive?

Thanks!




More information about the openwrt-devel mailing list