From owner-freebsd-bugs@FreeBSD.ORG Thu Apr 24 01:50:16 2003 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DBCB637B401 for ; Thu, 24 Apr 2003 01:50:16 -0700 (PDT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id AD21E43F3F for ; Thu, 24 Apr 2003 01:50:15 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.9/8.12.9) with ESMTP id h3O8oFUp016817 for ; Thu, 24 Apr 2003 01:50:15 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.9/8.12.9/Submit) id h3O8oFow016814; Thu, 24 Apr 2003 01:50:15 -0700 (PDT) Resent-Date: Thu, 24 Apr 2003 01:50:15 -0700 (PDT) Resent-Message-Id: <200304240850.h3O8oFow016814@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, land@dnepr.net Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 04B8E37B401 for ; Thu, 24 Apr 2003 01:41:52 -0700 (PDT) Received: from gx.dnepr.net (gx.dnepr.net [217.198.131.109]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0DD5C43FD7 for ; Thu, 24 Apr 2003 01:41:51 -0700 (PDT) (envelope-from land@gx.dnepr.net) Received: by gx.dnepr.net (Postfix, from userid 1000) id A51A7A8927; Thu, 24 Apr 2003 11:41:46 +0300 (EEST) Message-Id: <20030424084146.A51A7A8927@gx.dnepr.net> Date: Thu, 24 Apr 2003 11:41:46 +0300 (EEST) From: land@dnepr.net To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Subject: kern/51341: ipfw rule 'deny icmp from any to any icmptype 5' matches fragmented icmp packets X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Apr 2003 08:50:17 -0000 >Number: 51341 >Category: kern >Synopsis: ipfw rule 'deny icmp from any to any icmptype 5' matches fragmented icmp packets >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Thu Apr 24 01:50:13 PDT 2003 >Closed-Date: >Last-Modified: >Originator: land@dnepr.net >Release: FreeBSD 4.7-RELEASE >Organization: >Environment: System: FreeBSD 4.7-RELEASE i386 >Description: IPFW1 rule 'deny icmp from any to any icmptype 5' matches fragmented ICMP packets. >How-To-Repeat: ipfw add 1 deny icmp from any to any icmptype 5 Try to ping external host with big ICMP packets: ping -s 2000 host >Fix: >Release-Note: >Audit-Trail: >Unformatted: