In utils.crypto.constant_time_compare only call ord on non ints.
|Reported by:||adsworth||Owned by:||adsworth|
|Has patch:||yes||Needs documentation:||no|
|Needs tests:||no||Patch needs improvement:||no|
Iterating over a byte string in Python 3 will yield ints. Make sure that ord is only called on non ints.
Change History (10)
Changed 4 years ago by adsworth
comment:1 Changed 3 years ago by lukeplant
- Needs documentation unset
- Needs tests unset
- Patch needs improvement set
- Triage Stage changed from Unreviewed to Accepted
Changed 3 years ago by adsworth
comment:7 Changed 3 years ago by Aymeric Augustin <aymeric.augustin@…>
- Resolution set to fixed
- Status changed from new to closed