diff options
author | Markus Friedl <markus@cvs.openbsd.org> | 2011-04-06 19:15:35 +0000 |
---|---|---|
committer | Markus Friedl <markus@cvs.openbsd.org> | 2011-04-06 19:15:35 +0000 |
commit | 38b1eafd3637f833b0f7cfa2fdf61686414f6e64 (patch) | |
tree | ba641fc3cc7a699c8c7af1905685ef98e9bc87b0 /bin | |
parent | 70b43498012fa8f02468f62baf89711bcabcccb5 (diff) |
uncompress a packet with an IPcomp header only once; this prevents
endless loops by IPcomp-quine attacks as discovered by Tavis Ormandy;
it also prevents nested IPcomp-IPIP-IPcomp attacks provied by matthew@;
feedback and ok matthew@, deraadt@, djm@, claudio@
Diffstat (limited to 'bin')
0 files changed, 0 insertions, 0 deletions