The loop did not verify that the option buffer is large enough before
reading an address.
Reported by: Andrew Griffiths <andrew@calif.io>
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential D60484
dhclient: Avoid out-of-bounds reads in check_classless_option() Authored by markj on Thu, Oct 8, 6:04 PM. Tags None Referenced Files
Subscribers
Details
The loop did not verify that the option buffer is large enough before Reported by: Andrew Griffiths <andrew@calif.io>
Diff Detail
|