Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit 060ec30

Browse filesBrowse files
author
Federico Fissore
committed
GPGSignatureVerification: better error handling when reading signature
1 parent 0c123d7 commit 060ec30
Copy full SHA for 060ec30

File tree

Expand file treeCollapse file tree

1 file changed

+10
-1
lines changed
Filter options
Expand file treeCollapse file tree

1 file changed

+10
-1
lines changed

‎arduino-core/src/cc/arduino/contributions/GPGDetachedSignatureVerifier.java

Copy file name to clipboardExpand all lines: arduino-core/src/cc/arduino/contributions/GPGDetachedSignatureVerifier.java
+10-1Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,16 @@ public boolean verify(File signedFile, File signature, File publicKey) throws IO
5858
signatureInputStream = new FileInputStream(signature);
5959
PGPObjectFactory pgpObjectFactory = new PGPObjectFactory(signatureInputStream, new BcKeyFingerprintCalculator());
6060

61-
PGPSignatureList pgpSignatureList = (PGPSignatureList) pgpObjectFactory.nextObject();
61+
Object nextObject;
62+
try {
63+
nextObject = pgpObjectFactory.nextObject();
64+
if (!(nextObject instanceof PGPSignatureList)) {
65+
return false;
66+
}
67+
} catch (IOException e) {
68+
return false;
69+
}
70+
PGPSignatureList pgpSignatureList = (PGPSignatureList) nextObject;
6271
assert pgpSignatureList.size() == 1;
6372
PGPSignature pgpSignature = pgpSignatureList.get(0);
6473

0 commit comments

Comments
0 (0)
Morty Proxy This is a proxified and sanitized view of the page, visit original site.