Re: Buffer Copy without Checking Size of Input (CVE-2016-6559)

Paul Goyette <[email protected]> Wed, 7 Dec 2016 16:13:36 +0800 (PHT)
Newsgroups gmane.os.netbsd.devel.security
Message-ID <[email protected]>
This was fixed in NetBSD several hours ago.

On Wed, 7 Dec 2016, [email protected] wrote:

>> I just noticed this post:
>> https://www.kb.cert.org/vuls/id/548487
>> ...
>> Is someone working on this?
>
> The side-by-side view of yesterdays fix in FreeBSD looks like this:
>
> https://svnweb.freebsd.org/base/head/lib/libc/net/linkaddr.c?r1=288045&r2=309639
>
> and their original version was quite similar to the one in NetBSD.
>
> Kai-Uwe
>
>
>
>
>
> !DSPAM:5847c185285302011024860!
>
>

+------------------+--------------------------+------------------------+
| Paul Goyette     | PGP Key fingerprint:     | E-mail addresses:      |
| (Retired)        | FA29 0E3B 35AF E8AE 6651 | paul at whooppee.com   |
| Kernel Developer | 0786 F758 55DE 53BA 7731 | pgoyette at netbsd.org |
+------------------+--------------------------+------------------------+