diff options
author | Rich Felker <dalias@aerifal.cx> | 2017-10-18 14:50:03 -0400 |
---|---|---|
committer | Rich Felker <dalias@aerifal.cx> | 2017-10-18 14:50:03 -0400 |
commit | 45ca5d3fcb6f874bf5ba55d0e9651cef68515395 (patch) | |
tree | 277fae4ad1db979b38153b3118323ffe98a0a549 /arch/i386/bits | |
parent | 5b5eb527c5ed5ca2786bf82892a04ca3bdf33d31 (diff) | |
download | musl-45ca5d3fcb6f874bf5ba55d0e9651cef68515395.tar.gz musl-45ca5d3fcb6f874bf5ba55d0e9651cef68515395.tar.xz musl-45ca5d3fcb6f874bf5ba55d0e9651cef68515395.zip |
in dns parsing callback, enforce MAXADDRS to preclude overflow
MAXADDRS was chosen not to need enforcement, but the logic used to compute it assumes the answers received match the RR types of the queries. specifically, it assumes that only one replu contains A record answers. if the replies to both the A and the AAAA query have their answer sections filled with A records, MAXADDRS can be exceeded and clobber the stack of the calling function. this bug was found and reported by Felix Wilhelm.
Diffstat (limited to 'arch/i386/bits')
0 files changed, 0 insertions, 0 deletions