Re: [BUG][PATCH] Someone described a remote DoS Vulnerability in telnetd (dereference NULL pointer ---> SEGV)

Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]>
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <[email protected]>
Erik Auerswald <[email protected]> writes:

>> I have attached a completely untested, not even compile
>> tested, patch to do this (just the code changes, no NEWS
>> or commit log or anything).  Please test before committing.
>
> I have tested the patch now, it compiles and prevents the
> crash by preventing the NULL pointer dereference.

Thanks -- looks good to me, would you like to commit it?  Please add a
suitable NEWS entry.

Do you see any way to check for regressions that doesn't involve running
telnetd/telnet on the command line?  I'm thinking a automake C check
that links to relevant internals.

A new release would be nice, maybe we can throw in some other
improvement as well.

/Simon
signature.asc (application/pgp-signature, 255 B)
-----BEGIN PGP SIGNATURE-----

iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCYw53ERQcc2ltb25Aam9z
ZWZzc29uLm9yZwAKCRBRcisI/kdFollHAP9vjRmfh2zdu5Pvzi9kDJCAoEyweylf
tykbyyf6+CkdVAD/esubYrsuGZI5zSG4UJBt6tkQdnsNdY/BImfbjR0T+QY=
=Sf48
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.