commit | 308687b7d73c5cacf927a3a33efbfaea627ccc09 | [log] [tgz] |
---|---|---|
author | Denis Ovsienko <infrastation@yandex.ru> | Mon Sep 26 13:18:36 2011 +0400 |
committer | Denis Ovsienko <infrastation@yandex.ru> | Mon Sep 26 18:40:30 2011 +0400 |
tree | 5a6892a966b268e278e24f610322e1404216b730 | |
parent | 1f54cef38dab072f1054c6cfedd9ac32af14a120 [diff] |
ospf6d: CVE-2011-3324 (DD LSA assertion) This vulnerability (CERT-FI #514839) was reported by CROSS project. When Database Description LSA header list contains trailing zero octets, ospf6d tries to process this data as an LSA header. This triggers an assertion in the code and ospf6d shuts down. * ospf6_lsa.c * ospf6_lsa_is_changed(): handle header-only argument(s) appropriately, do not treat LSA length underrun as a fatal error.