]> git.ipfire.org Git - thirdparty/strongswan.git/commitdiff
ikev1: Properly handle fragmented Quick Mode messages
authorTobias Brunner <tobias@strongswan.org>
Tue, 30 Jan 2018 10:33:15 +0000 (11:33 +0100)
committerTobias Brunner <tobias@strongswan.org>
Fri, 9 Feb 2018 09:46:00 +0000 (10:46 +0100)
src/libcharon/encoding/message.c

index 6d850aac05e2d47d2f8e26920d8ef73d957f792a..735526e3c086c6ca2a1c61756f27b4abe09d783e 100644 (file)
@@ -657,6 +657,7 @@ static payload_rule_t quick_mode_i_rules[] = {
        {PLV1_ID,                                               0,      2,                                              TRUE,   FALSE},
        {PLV1_NAT_OA,                                   0,      2,                                              TRUE,   FALSE},
        {PLV1_NAT_OA_DRAFT_00_03,               0,      2,                                              TRUE,   FALSE},
+       {PLV1_FRAGMENT,                                 0,      1,                                              FALSE,  TRUE},
 };
 
 /**
@@ -673,6 +674,7 @@ static payload_order_t quick_mode_i_order[] = {
        {PLV1_ID,                                               0},
        {PLV1_NAT_OA,                                   0},
        {PLV1_NAT_OA_DRAFT_00_03,               0},
+       {PLV1_FRAGMENT,                                 0},
 };
 
 /**
@@ -689,6 +691,7 @@ static payload_rule_t quick_mode_r_rules[] = {
        {PLV1_ID,                                               0,      2,                                              TRUE,   FALSE},
        {PLV1_NAT_OA,                                   0,      2,                                              TRUE,   FALSE},
        {PLV1_NAT_OA_DRAFT_00_03,               0,      2,                                              TRUE,   FALSE},
+       {PLV1_FRAGMENT,                                 0,      1,                                              FALSE,  TRUE},
 };
 
 /**
@@ -705,6 +708,7 @@ static payload_order_t quick_mode_r_order[] = {
        {PLV1_ID,                                               0},
        {PLV1_NAT_OA,                                   0},
        {PLV1_NAT_OA_DRAFT_00_03,               0},
+       {PLV1_FRAGMENT,                                 0},
 };
 
 /**