Project

General

Profile

Actions

Security #6675

closed

ip-defrag: packet can be considered complete even with holes

Added by Jason Ish 10 months ago. Updated 6 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
Git IDs:

d226d0a3fce8837936e1bdfaee496c80d417e0a5

Severity:
MODERATE
Disclosure Date:

Description

The test to check if all fragments exist is flawed. It adds up the data lengths, which can cause it to be larger than the data available in case of fragments.

To fix, the length of the re-assembled packet should only be incremented to the last byte of data seen.

This is covered by test peose/bsd/173


Subtasks 2 (0 open2 closed)

Security #6676: ip-defrag: packet can be considered complete even with holes (6.0.x backport)ClosedJason IshActions
Security #6677: ip-defrag: packet can be considered complete even with holes (7.0.x backport)ClosedJason IshActions
Actions

Also available in: Atom PDF