Florian Westphal
e93b5f9f32
netfilter: cttimeout: fix buffer overflow
...
Chen Gang reports:
the length of nla_data(cda[CTA_TIMEOUT_NAME]) is not limited in server side.
And indeed, its used to strcpy to a fixed-sized buffer.
Fortunately, nfnetlink users need CAP_NET_ADMIN.
Reported-by: Chen Gang <gang.chen@asianux.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2012-11-21 23:50:14 +01:00
..
2012-11-21 23:49:02 +01:00
2012-10-17 10:59:20 +02:00
2012-09-03 13:52:54 +02:00
2012-09-21 12:12:05 +02:00
2012-09-21 12:12:05 +02:00
2012-04-20 21:22:30 -04:00
2012-08-30 03:00:21 +02:00
2012-09-21 11:35:18 +02:00
2012-09-10 15:30:41 -04:00
2012-08-16 11:49:53 +02:00
2012-06-16 15:08:49 +02:00
2012-09-24 14:29:40 +02:00
2012-10-22 12:21:55 +02:00
2012-06-19 01:24:52 +02:00
2012-08-30 03:00:23 +02:00
2012-09-24 14:29:40 +02:00
2012-08-30 03:00:13 +02:00
2012-06-27 19:14:31 +02:00
2012-07-04 19:37:22 +02:00
2012-06-27 18:31:14 +02:00
2012-06-27 19:13:31 +02:00
2012-09-15 11:43:53 -04:00
2012-07-04 19:37:22 +02:00
2012-06-27 19:12:52 +02:00
2012-08-20 12:46:29 +02:00
2012-06-16 15:08:55 +02:00
2012-08-30 03:00:22 +02:00
2012-04-20 21:22:30 -04:00
2012-08-30 03:00:24 +02:00
2012-03-07 17:41:25 +01:00
2012-04-20 21:22:30 -04:00
2012-09-03 13:52:54 +02:00
2012-04-20 21:22:30 -04:00
2012-08-30 03:00:21 +02:00
2012-09-21 12:09:25 +02:00
2012-08-30 03:00:20 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:23 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-08-30 03:00:14 +02:00
2012-09-03 15:34:51 +02:00
2012-08-30 03:00:24 +02:00
2012-09-03 13:52:54 +02:00
2012-09-10 15:30:41 -04:00
2012-09-24 14:29:40 +02:00
2012-11-21 23:50:14 +01:00
2012-10-02 13:38:27 -07:00
2012-09-24 15:10:29 +02:00
2012-06-23 02:13:38 +02:00
2012-09-08 18:46:30 -04:00
2012-06-07 14:58:39 +02:00
2012-10-15 13:38:58 +02:00
2012-05-17 00:56:31 +02:00
2012-06-07 14:53:01 +02:00
2012-09-26 01:33:16 +02:00
2012-10-02 11:11:09 -07:00
2012-05-09 20:49:18 -04:00
2012-10-15 13:39:12 +02:00
2012-09-21 12:11:08 +02:00
2012-08-20 12:45:57 +02:00
2012-08-20 12:45:57 +02:00
2012-08-14 21:55:30 -07:00
2012-08-14 21:55:29 -07:00
2012-09-21 12:12:05 +02:00
2012-09-22 22:44:34 +02:00
2012-09-03 13:31:39 +02:00
2012-05-15 13:45:03 -04:00
2012-10-17 11:00:31 +02:00
2012-09-24 14:29:01 +02:00
2012-07-10 23:13:45 -07:00