diff options
author | Alexander Bluhm <bluhm@cvs.openbsd.org> | 2019-03-20 20:07:29 +0000 |
---|---|---|
committer | Alexander Bluhm <bluhm@cvs.openbsd.org> | 2019-03-20 20:07:29 +0000 |
commit | ceaa56f81bdfd1b57594eaf9b9973fe9a1d390cc (patch) | |
tree | 45885ee4d3727654a521d0b0524f2a43dec672c1 /sbin/dhclient/clparse.c | |
parent | d78036c7a2473520d65a7069d1cc5152aa160c19 (diff) |
States in pf(4) let ICMP and ICMP6 packets pass if they have a
packet in their payload that matches an exiting connection. It was
not checked whether the outer ICMP packet has the same destination
IP as the source IP of the inner protocol packet. Enforce that
these addresses match, to prevent ICMP packets that do not make
sense.
Issue found by Nicolas Collignon, Corentin Bayet, Eloi Vanderbeken,
Luca Moro at Synacktiv.com
OK sashan@
Diffstat (limited to 'sbin/dhclient/clparse.c')
0 files changed, 0 insertions, 0 deletions