diff --git a/asn1-parser.js b/asn1-parser.js index 294273e..e001e88 100644 --- a/asn1-parser.js +++ b/asn1-parser.js @@ -1,3 +1,7 @@ +// Copyright 2018 AJ ONeal. All rights reserved +/* This Source Code Form is subject to the terms of the Mozilla Public + * License, v. 2.0. If a copy of the MPL was not distributed with this + * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ ;(function (exports) { 'use strict'; @@ -13,8 +17,10 @@ var PEM = exports.PEM; // Parser // -ASN1.ELOOP = "uASN1.js Error: iterated over 15+ elements (probably a malformed file)"; -ASN1.EDEEP = "uASN1.js Error: element nested 20+ layers deep (probably a malformed file)"; +ASN1.ELOOPN = 20; // I've seen 9 max in https certificates +ASN1.ELOOP = "uASN1.js Error: iterated over " + ASN1.ELOOPN + "+ elements (probably a malformed file)"; +ASN1.EDEEPN = 60; // I've seen 29 deep in https certificates +ASN1.EDEEP = "uASN1.js Error: element nested " + ASN1.EDEEPN + "+ layers deep (probably a malformed file)"; // Container Types are Sequence 0x30, Container Array? (0xA0, 0xA1) // Value Types are Boolean 0x01, Integer 0x02, Null 0x05, Object ID 0x06, String 0x0C, 0x16, 0x13, 0x1e Value Array? (0x82) // Bit String (0x03) and Octet String (0x04) may be values or containers @@ -24,7 +30,7 @@ ASN1.VTYPES = [ 0x01, 0x02, 0x05, 0x06, 0x0c, 0x82 ]; ASN1.parse = function parseAsn1Helper(buf) { //var ws = ' '; function parseAsn1(buf, depth) { - if (depth.length >= 20) { throw new Error(ASN1.EDEEP); } + if (depth.length >= ASN1.EDEEPN) { throw new Error(ASN1.EDEEP); } var index = 2; // we know, at minimum, data starts after type (0) and lengthSize (1) var asn1 = { type: buf[0], lengthSize: 0, length: buf[1] }; @@ -57,7 +63,7 @@ ASN1.parse = function parseAsn1Helper(buf) { function parseChildren(eager) { asn1.children = []; //console.warn('1 len:', (2 + asn1.lengthSize + asn1.length), 'idx:', index, 'clen:', 0); - while (iters < 15 && index < (2 + asn1.length + asn1.lengthSize)) { + while (iters < ASN1.ELOOPN && index < (2 + asn1.length + asn1.lengthSize)) { iters += 1; depth.length += 1; child = parseAsn1(buf.slice(index, index + adjustedLen), depth); @@ -78,7 +84,7 @@ ASN1.parse = function parseAsn1Helper(buf) { //console.warn('index:', index, 'length:', (2 + asn1.lengthSize + asn1.length)); throw new Error("premature end-of-file"); } - if (iters >= 15) { throw new Error(ASN1.ELOOP); } + if (iters >= ASN1.ELOOPN) { throw new Error(ASN1.ELOOP); } delete asn1.value; return asn1; diff --git a/package.json b/package.json index 822cc69..3c9cdf8 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "asn1-parser", - "version": "1.1.4", + "version": "1.1.5", "description": "An ASN.1 parser in less than 100 lines of Vanilla JavaScript, part of the Bluecrypt suite.", "homepage": "https://git.coolaj86.com/coolaj86/asn1-parser.js", "main": "asn1-parser.js",