Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-20:10.ipfw

Eugene Grosbein <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
21.04.2020 23:55, FreeBSD Security Advisories wrote:
> =============================================================================
> FreeBSD-SA-20:10.ipfw                                       Security Advisory
>                                                           The FreeBSD Project
> 
> Topic:          ipfw invalid mbuf handling

[skip]

> IV.  Workaround
> 
> No workaround is available.  Systems not using the ipfw firewall are
> not vulnerable.

This is not true. The problem affects only seldom used rules matching TCP packets
by list of TCP options (rules with "tcpoptions" keyword) and/or by TCP MSS size
(rules with matching "tcpmss" keyword, don't mix with "tcp-setmss" action keyword).

Systems not using "tcpoptions" nor "tcpmss" keywords to match TCP packets are not affected.
For example, system using any of default templates (open/client/simple/closed/workstation) are not affected.

Please consider re-checking this and adjusting the Advisory.
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.