summaryrefslogtreecommitdiff
path: root/sbin/dhclient/clparse.c
diff options
context:
space:
mode:
authorAlexander Bluhm <bluhm@cvs.openbsd.org>2019-03-20 20:07:29 +0000
committerAlexander Bluhm <bluhm@cvs.openbsd.org>2019-03-20 20:07:29 +0000
commitceaa56f81bdfd1b57594eaf9b9973fe9a1d390cc (patch)
tree45885ee4d3727654a521d0b0524f2a43dec672c1 /sbin/dhclient/clparse.c
parentd78036c7a2473520d65a7069d1cc5152aa160c19 (diff)
States in pf(4) let ICMP and ICMP6 packets pass if they have a
packet in their payload that matches an exiting connection. It was not checked whether the outer ICMP packet has the same destination IP as the source IP of the inner protocol packet. Enforce that these addresses match, to prevent ICMP packets that do not make sense. Issue found by Nicolas Collignon, Corentin Bayet, Eloi Vanderbeken, Luca Moro at Synacktiv.com OK sashan@
Diffstat (limited to 'sbin/dhclient/clparse.c')
0 files changed, 0 insertions, 0 deletions