Skip to content

吞异常,太恶心了。org.bouncycastle.crypto.signers.SM2Signer#verifySignature(byte[]) #2237

@wangzongying

Description

@wangzongying

这个sm2验签方法吞异常,当传入的签名值不太符合规范时,或者BigInteger是无符号数,导致解析为负数时,异常被吞。直接返回false。害人不浅。

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions