]> git.ipfire.org Git - thirdparty/dhcp.git/commit
[#182] Corrected CVE: CVE-2021-25217
authorThomas Markwalder <tmark@isc.org>
Thu, 13 May 2021 17:22:29 +0000 (13:22 -0400)
committerWlodek Wencel <wlodek@isc.org>
Tue, 25 Jan 2022 17:25:58 +0000 (18:25 +0100)
commit3d53b2f2a0369c2af83c738d4e8194077315cbb4
treee14f8c48e975d8f39be0819ecd6c27ea9c482612
parentb2ca192e648a33feed6c25989d0fe4be9cc93f6e
[#182] Corrected CVE: CVE-2021-25217

Addressed buffer overwrite in parse_X()

Added Release Note

common/parse.c
    parse_X() - reworked to avoid buffer overwrite on
    over-sized hex literals

common/tests/option_unittest.c
    ATF_TC_BODY(parse_X) - new test which verifies
    parse_X() logic.
RELNOTES
common/parse.c
common/tests/option_unittest.c