Skip to content

吞异常,太恶心了。org.bouncycastle.crypto.signers.SM2Signer#verifySignature(byte[]) #2237

@wangzongying

Description

@wangzongying

这个sm2验签方法吞异常,当传入的签名值不太符合规范时,或者BigInteger是无符号数,导致解析为负数时,异常被吞。直接返回false。害人不浅。

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions