From owner-cvs-src@FreeBSD.ORG Sun Mar 6 14:44:38 2005 Return-Path: Delivered-To: cvs-src@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B91D016A4CE; Sun, 6 Mar 2005 14:44:38 +0000 (GMT) Received: from postfix3-2.free.fr (postfix3-2.free.fr [213.228.0.169]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1EA4C43D1F; Sun, 6 Mar 2005 14:44:37 +0000 (GMT) (envelope-from tataz@tataz.chchile.org) Received: from tatooine.tataz.chchile.org (vol75-8-82-233-239-98.fbx.proxad.net [82.233.239.98]) by postfix3-2.free.fr (Postfix) with ESMTP id 96638C114; Sun, 6 Mar 2005 15:44:33 +0100 (CET) Received: by tatooine.tataz.chchile.org (Postfix, from userid 1000) id 87515407C; Sun, 6 Mar 2005 15:43:47 +0100 (CET) Date: Sun, 6 Mar 2005 15:43:47 +0100 From: Jeremie Le Hen To: Joe Marcus Clarke Message-ID: <20050306144347.GA74191@obiwan.tataz.chchile.org> References: <200503060800.j26803h3049872@repoman.freebsd.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200503060800.j26803h3049872@repoman.freebsd.org> User-Agent: Mutt/1.5.7i cc: cvs-src@FreeBSD.org cc: src-committers@FreeBSD.org cc: cvs-all@FreeBSD.org Subject: Re: cvs commit: src/lib/libalias alias_skinny.c X-BeenThere: cvs-src@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Mar 2005 14:44:38 -0000 Hi, > marcus 2005-03-06 08:00:03 UTC > > FreeBSD src repository (doc,ports committer) > > Modified files: (Branch: RELENG_5) > lib/libalias alias_skinny.c > Log: > MFC: rev 1.8 > > Fix a problem in the Skinny ALG where a specially crafted packet could cause > a libalias application (e.g. natd, ppp, etc.) to crash. Note: Skinny support > is not enabled in natd or ppp by default. > > Approved by: re (kensmith) > Security: This fixes a remote DoS exploit Will this be fixed in RELENG_4 as well ? Regards, -- Jeremie Le Hen jeremie at le-hen dot org