Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 25 Feb 2015 05:43:03 +0000 (UTC)
From:      Xin LI <delphij@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-8@freebsd.org
Subject:   svn commit: r279263 - in stable: 10/sys/netinet 8/sys/netinet 9/sys/netinet
Message-ID:  <201502250543.t1P5h378083359@svn.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: delphij
Date: Wed Feb 25 05:43:02 2015
New Revision: 279263
URL: https://svnweb.freebsd.org/changeset/base/279263

Log:
  Instant MFC:
  
  Fix integer overflow in IGMP protocol.
  
  Security:	FreeBSD-SA-15:04.igmp
  Security:	CVE-2015-1414
  Found by:	Mateusz Kocielski, Logicaltrust
  Analyzed by:	Marek Kroemeke, Mateusz Kocielski (shm@NetBSD.org) and
  		22733db72ab3ed94b5f8a1ffcde850251fe6f466
  Submited by:	Mariusz Zaborski <oshogbo@FreeBSD.org>
  Reviewed by:	bms
  Approved by:	so

Modified:
  stable/8/sys/netinet/igmp.c

Changes in other areas also in this revision:
Modified:
  stable/10/sys/netinet/igmp.c
  stable/9/sys/netinet/igmp.c

Modified: stable/8/sys/netinet/igmp.c
==============================================================================
--- stable/8/sys/netinet/igmp.c	Wed Feb 25 05:42:59 2015	(r279262)
+++ stable/8/sys/netinet/igmp.c	Wed Feb 25 05:43:02 2015	(r279263)
@@ -1532,8 +1532,8 @@ igmp_input(struct mbuf *m, int off)
 		case IGMP_VERSION_3: {
 				struct igmpv3 *igmpv3;
 				uint16_t igmpv3len;
-				uint16_t srclen;
-				int nsrc;
+				uint16_t nsrc;
+				int srclen;
 
 				IGMPSTAT_INC(igps_rcv_v3_queries);
 				igmpv3 = (struct igmpv3 *)igmp;



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201502250543.t1P5h378083359>