HomeFreeBSD

bootpd: validate hardware type

Description

bootpd: validate hardware type

Due to insufficient validation of network-provided data it may have been
possible for a malicious actor to craft a bootp packet which could cause
a stack buffer overflow.

admbugs: 850
Reported by: Reno Robert
Reviewed by: markj
Approved by: so
Security: FreeBSD-SA-18:15.bootpd
Sponsored by: The FreeBSD Foundation

Details

Provenance
emasteAuthored on Dec 19 2018, 6:16 PM
Parents
rG53941c0a736c: Replace uses of sbadaddr with stval.
Branches
Unknown
Tags
Unknown

Event Timeline