Re: Fw: Netrom module vulnerability

From: Tomi Manninen (ctt@wa.us)
Date: Sun Nov 11 2001 - 01:43:46 EET

  • Next message: Paula Dowie: "Re: Fw: Netrom module vulnerability"

    On Sun, 11 Nov 2001, Paula Dowie wrote:

    > As I said, this is my first look at Linux code, so I may have misunderstood
    > something. If so, could someone more knowledgeable please take this up and
    > fix the problem?

    Paula,

    you are exactly right on this one. It's something I noticed a few weeks
    ago while investigating another problem. There are other places in the
    NET/ROM code where similar checks need to be added.

    The guideline on network protocols I've heard goes something like "be
    liberal in what you accept and conservative in what you send". As I see
    that can be re-iterated as "check all incoming data very carefully". My
    excuse as the NET/ROM protocol stack maintainer is that I didn't write the
    code myself. :)

    And, btw, we Linux programmers (well I anyway) gladly accept bug reports
    from anyone. If someone manages to crash the Linux kernel with network
    input, it's definitely a Linux bug.

    -- 
    Tomi Manninen           Internet:  oziflee.wqrzulvzqm@mcbone.net
    OH2BNS                  AX.25:     rhwchr.huodjuwcan@bdo-it.com
    KP20ME04                Amprnet:   terhi.victor@logonet.com
    

    - To unsubscribe from this list: send the line "unsubscribe linux-hams" in the body of a message to terhi.victor@logonet.com More majordomo info at http://vger.kernel.org/majordomo-info.html



    This archive was generated by hypermail 2b30 : Sun Nov 11 2001 - 02:07:28 EET