Re: [BUG][PATCH] Someone described a remote DoS Vulnerability in telnetd (dereference NULL pointer ---> SEGV)
Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]>
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <[email protected]> |
Erik Auerswald <[email protected]> writes: >> I have attached a completely untested, not even compile >> tested, patch to do this (just the code changes, no NEWS >> or commit log or anything). Please test before committing. > > I have tested the patch now, it compiles and prevents the > crash by preventing the NULL pointer dereference. Thanks -- looks good to me, would you like to commit it? Please add a suitable NEWS entry. Do you see any way to check for regressions that doesn't involve running telnetd/telnet on the command line? I'm thinking a automake C check that links to relevant internals. A new release would be nice, maybe we can throw in some other improvement as well. /Simon
signature.asc
(application/pgp-signature, 255 B)
-----BEGIN PGP SIGNATURE----- iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCYw53ERQcc2ltb25Aam9z ZWZzc29uLm9yZwAKCRBRcisI/kdFollHAP9vjRmfh2zdu5Pvzi9kDJCAoEyweylf tykbyyf6+CkdVAD/esubYrsuGZI5zSG4UJBt6tkQdnsNdY/BImfbjR0T+QY= =Sf48 -----END PGP SIGNATURE-----