]> The Tcpdump Group git mirrors - tcpdump/commitdiff
CVE-2017-13035/Properly handle IS-IS IDs shorter than a system ID (MAC address).
authorGuy Harris <[email protected]>
Thu, 23 Mar 2017 21:37:56 +0000 (14:37 -0700)
committerDenis Ovsienko <[email protected]>
Sun, 3 Sep 2017 23:08:58 +0000 (00:08 +0100)
Some of them are variable-length, with a field giving the total length,
and therefore they can be shorter than 6 octets.  If one is, don't run
past the end.

This fixes a buffer over-read discovered by Bhargava Shastry,
SecT/TU Berlin.

Add a test using the capture file supplied by the reporter(s), modified
so the capture file won't be rejected as an invalid capture.


No differences found