From c1587fcf1e9ed87b16e285339e5deb3336665eb0 Mon Sep 17 00:00:00 2001 From: Paul Kehrer Date: Sat, 6 Jun 2015 00:56:00 -0500 Subject: don't double free DSA cdata when verifying things --- src/cryptography/hazmat/backends/openssl/dsa.py | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/src/cryptography/hazmat/backends/openssl/dsa.py b/src/cryptography/hazmat/backends/openssl/dsa.py index 5d7ca38c..254d29ed 100644 --- a/src/cryptography/hazmat/backends/openssl/dsa.py +++ b/src/cryptography/hazmat/backends/openssl/dsa.py @@ -40,13 +40,10 @@ class _DSAVerificationContext(object): self._hash_ctx.update(data) def verify(self): - self._dsa_cdata = self._backend._ffi.gc(self._public_key._dsa_cdata, - self._backend._lib.DSA_free) - data_to_verify = self._hash_ctx.finalize() data_to_verify = _truncate_digest_for_dsa( - self._dsa_cdata, data_to_verify, self._backend + self._public_key._dsa_cdata, data_to_verify, self._backend ) # The first parameter passed to DSA_verify is unused by OpenSSL but -- cgit v1.2.3