diff --git a/ChangeLog b/ChangeLog index 7f76b7fc2..12bbaf051 100644 --- a/ChangeLog +++ b/ChangeLog @@ -7,6 +7,7 @@ Changes Bugfix * Fixed X.509 hostname comparison (with non-regular characters) * SSL now gracefully handles missing RNG + * crypt_and_hash app checks MAC before final decryption = Version 1.2.10 released 2013-10-07 Changes diff --git a/programs/aes/crypt_and_hash.c b/programs/aes/crypt_and_hash.c index 37d9d3093..0448440a7 100644 --- a/programs/aes/crypt_and_hash.c +++ b/programs/aes/crypt_and_hash.c @@ -453,17 +453,6 @@ int main( int argc, char *argv[] ) } } - /* - * Write the final block of data - */ - cipher_finish( &cipher_ctx, output, &olen ); - - if( fwrite( output, 1, olen, fout ) != olen ) - { - fprintf( stderr, "fwrite(%ld bytes) failed\n", (long) olen ); - goto exit; - } - /* * Verify the message authentication code. */ @@ -486,6 +475,17 @@ int main( int argc, char *argv[] ) "or file corrupted.\n" ); goto exit; } + + /* + * Write the final block of data + */ + cipher_finish( &cipher_ctx, output, &olen ); + + if( fwrite( output, 1, olen, fout ) != olen ) + { + fprintf( stderr, "fwrite(%ld bytes) failed\n", (long) olen ); + goto exit; + } } ret = 0;