[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20121121225436.GB19941@1984>
Date: Wed, 21 Nov 2012 23:54:36 +0100
From: Pablo Neira Ayuso <pablo@...filter.org>
To: Florian Westphal <fw@...len.de>
Cc: netfilter-devel <netfilter-devel@...r.kernel.org>,
netdev <netdev@...r.kernel.org>
Subject: Re: [PATCH 1/1] netfilter: cttimeout: fix buffer overflow
On Wed, Nov 21, 2012 at 12:37:38PM +0100, Florian Westphal wrote:
> Chen Gang reports:
> the length of nla_data(cda[CTA_TIMEOUT_NAME]) is not limited in server side.
>
> And indeed, its used to strcpy to a fixed-sized buffer.
>
> Fortunately, nfnetlink users need CAP_NET_ADMIN.
Good catch, applied thanks.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists