Re: off-by-one error in ip_fragment, recently.

From: David Gilbert <dgilbert_at_dclg.ca>
Date: Sun, 11 Jan 2004 22:40:03 -0500
Further in followup to the ip_fragment() bug, at the crash, off =
1500, len = 1480 and ip->ip_len = 21248.  So m_copym() is being called
with off > len.

Dave.

-- 
============================================================================
|David Gilbert, Independent Contractor.       | Two things can only be     |
|Mail:       dave_at_daveg.ca                    |  equal if and only if they |
|http://daveg.ca                              |   are precisely opposite.  |
=========================================================GLO================
Received on Sun Jan 11 2004 - 18:47:35 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:37 UTC