From owner-freebsd-bugs@FreeBSD.ORG Mon May 10 13:00:42 2004 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E033B16A4CE for ; Mon, 10 May 2004 13:00:42 -0700 (PDT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 665F343D1D for ; Mon, 10 May 2004 13:00:42 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) i4AK0gcs013630 for ; Mon, 10 May 2004 13:00:42 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.11/8.12.11/Submit) id i4AK0g5o013629; Mon, 10 May 2004 13:00:42 -0700 (PDT) (envelope-from gnats) Date: Mon, 10 May 2004 13:00:42 -0700 (PDT) Message-Id: <200405102000.i4AK0g5o013629@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Andrei Iltchenko Subject: Re: kern/66386: Buffer overrun in the 'in_pcbopts' function. X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Andrei Iltchenko List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 May 2004 20:00:43 -0000 The following reply was made to PR kern/66386; it has been noted by GNATS. From: Andrei Iltchenko To: Maxim Konovalov Cc: bug-followup@freebsd.org Subject: Re: kern/66386: Buffer overrun in the 'in_pcbopts' function. Date: Mon, 10 May 2004 12:53:14 -0700 (PDT) Yes, I did mean "(unsigned)cnt - (IPOPT_MINOFF - 1))". Sorry for the slipup. Regards, Andrei. --- Maxim Konovalov wrote: > > Did you mean "(unsigned)cnt - (IPOPT_MINOFF - 1))"? > > Index: ip_output.c > =================================================================== > RCS file: /home/ncvs/src/sys/netinet/ip_output.c,v > retrieving revision 1.215 > diff -u -r1.215 ip_output.c > --- ip_output.c 14 Apr 2004 01:13:14 -0000 1.215 > +++ ip_output.c 9 May 2004 13:40:41 -0000 > @@ -1735,7 +1735,7 @@ > */ > bcopy((&cp[IPOPT_OFFSET+1] + sizeof(struct > in_addr)), > &cp[IPOPT_OFFSET+1], > - (unsigned)cnt + sizeof(struct in_addr)); > + (unsigned)cnt - (IPOPT_MINOFF - 1)); > break; > } > } > %%% > > -- > Maxim Konovalov __________________________________ Do you Yahoo!? Win a $20,000 Career Makeover at Yahoo! HotJobs http://hotjobs.sweepstakes.yahoo.com/careermakeover