diff options
author | Denis Ovsienko <denis@ovsienko.info> | 2017-08-07 22:43:20 +0100 |
---|---|---|
committer | Denis Ovsienko <denis@ovsienko.info> | 2017-09-13 12:25:44 +0100 |
commit | 289c672020280529fd382f3502efab7100d638ec (patch) | |
tree | 9b21e2d82e45e547847989b40c46fd4c59e27af8 /print-rpki-rtr.c | |
parent | 331530a4076c69bbd2e3214db6ccbe834fb75640 (diff) | |
download | tcpdump-289c672020280529fd382f3502efab7100d638ec.tar.gz |
CVE-2017-13051/RSVP: fix bounds checks for UNI
Fixup the part of rsvp_obj_print() that decodes the GENERALIZED_UNI
object from RFC 3476 Section 3.1 to check the sub-objects inside that
object more thoroughly.
This fixes a buffer over-read discovered by Bhargava Shastry,
SecT/TU Berlin.
Add a test using the capture file supplied by the reporter(s).
Diffstat (limited to 'print-rpki-rtr.c')
0 files changed, 0 insertions, 0 deletions