From: Greg KH <greg@kroah.com>
To: Greg KH <gregkh@suse.de>,
linux-kernel@vger.kernel.org, stable@kernel.org,
Justin Forbes <jmforbes@linuxtx.org>,
Zwane Mwaikambo <zwane@arm.linux.org.uk>,
"Theodore Ts'o" <tytso@mit.edu>,
Randy Dunlap <rdunlap@xenotime.net>,
Dave Jones <davej@redhat.com>,
Chuck Wolber <chuckw@quantumlinux.com>,
torvalds@osdl.org, akpm@osdl.org, alan@lxorguk.ukuu.org.uk,
kaber@trash.net
Subject: Re: [stable] Re: [patch 6/6] [NETFILTER]: Fix another crash in ip_nat_pptp (CVE-2006-0037)
Date: Thu, 9 Feb 2006 20:47:54 -0800 [thread overview]
Message-ID: <20060210044754.GC27457@kroah.com> (raw)
In-Reply-To: <20060208123541.GA6004@kruemel.my-eitzenberger.de>
On Wed, Feb 08, 2006 at 01:35:41PM +0100, Holger Eitzenberger wrote:
> On Fri, Jan 27, 2006 at 06:18:35PM -0800, Greg KH wrote:
>
> > DEBUGP("altering call id from 0x%04x to 0x%04x\n",
> > - ntohs(*cid), ntohs(new_callid));
> > + ntohs(*(u_int16_t *)pptpReq + cid_off), ntohs(new_callid));
>
> Note that this fix introduces another bug in the above use DEBUGP
> statement, as there is (u_int16_t *) ptr arithmetic used, whereas
> cid_off is a byte offset.
>
> A fix for that was send a few weeks ago on netfilter-devel.
Great, care to forward it to stable@kernel.org so we can get it in the
next release?
thanks,
greg k-h
next prev parent reply other threads:[~2006-02-10 4:48 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20060128015840.722214000@press.kroah.org>
2006-01-28 2:17 ` [patch 0/6] 2.6.14.7 -stable review Greg KH
2006-01-28 2:18 ` [patch 1/6] setting irq affinity is broken in ia32 with MSI enabled Greg KH
2006-01-28 2:18 ` [patch 2/6] [EBTABLES] Don't match tcp/udp source/destination port for IP fragments Greg KH
2006-01-28 2:18 ` [patch 3/6] [SPARC64]: Fix ptrace/strace Greg KH
2006-01-28 2:18 ` [patch 4/6] [SPARC64]: Fix sys_fstat64() entry in 64-bit syscall table Greg KH
2006-01-28 2:18 ` [patch 5/6] [NETFILTER]: Fix crash in ip_nat_pptp (CVE-2006-0036) Greg KH
2006-01-28 2:18 ` [patch 6/6] [NETFILTER]: Fix another crash in ip_nat_pptp (CVE-2006-0037) Greg KH
2006-02-08 12:35 ` Holger Eitzenberger
2006-02-10 4:47 ` Greg KH [this message]
2006-02-10 4:57 ` [stable] " Andrew Morton
2006-02-10 5:08 ` Greg KH
2006-02-10 8:07 ` Harald Welte
2006-01-29 4:30 ` [patch 0/6] 2.6.14.7 -stable review Chuck Wolber
2006-01-29 4:43 ` Justin M. Forbes
2006-01-29 4:52 ` Chuck Wolber
2006-01-29 4:57 ` Randy.Dunlap
2006-01-29 5:34 ` Greg KH
2006-01-29 6:09 ` Willy Tarreau
2006-01-29 7:36 ` Chuck Wolber
2006-01-29 7:11 ` Chuck Wolber
2006-01-29 7:58 ` Chuck Wolber
2006-01-29 4:45 ` Randy.Dunlap
2006-01-29 5:02 ` Chuck Wolber
2006-01-29 6:17 ` Willy Tarreau
2006-01-29 7:43 ` Chuck Wolber
2006-01-31 15:05 ` Krzysztof Halasa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060210044754.GC27457@kroah.com \
--to=greg@kroah.com \
--cc=akpm@osdl.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=chuckw@quantumlinux.com \
--cc=davej@redhat.com \
--cc=gregkh@suse.de \
--cc=jmforbes@linuxtx.org \
--cc=kaber@trash.net \
--cc=linux-kernel@vger.kernel.org \
--cc=rdunlap@xenotime.net \
--cc=stable@kernel.org \
--cc=torvalds@osdl.org \
--cc=tytso@mit.edu \
--cc=zwane@arm.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.