checking packet size?

Horacio J. Peña <horape-8F+6uIJwPFXYBSKQQAhgz1q4uMLhaVOdqSblbbW8eSQ@public.gmane.org>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
Hola!

I'm writing a target for ebtables and reading ebt_log.c to learn how it
works, I see that it access the IP header without checking the size of
the payload. Wouldn't that create a vulnerability?

...

Just checked the 2.6 source, and there it seems to be "corrected".
Shouldn't that be backported to the 2.4 patch?

The 2.6 source does a skb_copy_bits of the payload. Is that the only way
of checking if the header is incomplete? It seems terrible from a
performance point of view.

Thanks,
					HoraPe
---
Horacio J. Peña
[email protected]
[email protected]


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_ide95&alloc_id396&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.