• OpenBSD 7.2 ip_srcroute() Overflow

    From Security Bot@2:467/4.444 to All on Fri Sep 22 11:22:00 2023


    OpenBSD 7.2 ip_srcroute() Overflow

    OpenBSD version 7.2 suffers from an overflow vulnerability. ip_dooptions()
    will allow IPOPT_SSRR with optlen = 2. save_rte() will set isr_nhops
    to very large value, which will cause an overflow in the next
    ip_srcroute() call.

    https://packetstormsecurity.com/files/171279/openbsd_tcpip_overflow-main.zip

    Tue, 07 Mar 2023 19:26:05 GMT
    ________________________________
    --- The information is for inforamtional purposes only.
    * Origin: Read us with http://winpoint.org JID: rs@captflint.com (2:467/4.444)