[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH 3/3] telnet: Avoid command evaluation crashes.
From: |
Guillem Jover |
Subject: |
Re: [PATCH 3/3] telnet: Avoid command evaluation crashes. |
Date: |
Sat, 3 Sep 2022 20:08:40 +0200 |
[ Removed Erik from To, as last time my mail was rejected by the mail
server, and might then not get delivered by mailman as duplicate. ]
Hi!
On Sat, 2022-09-03 at 19:07:52 +0200, Erik Auerswald wrote:
> AFAIK the other fuzzer-based crash reports have already been addressed
> before the release of GNU Inetutils 2.3:
You might want to take a look at:
<https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/tree/debian/patches/0004-telnet-Add-checks-for-option-reply-parsing-limits.patch>
The implementations in the BSDs are probably worth checking for
similar old fixes.
Thanks,
Guillem
- Re: [PATCH 3/3] telnet: Avoid command evaluation crashes., Erik Auerswald, 2022/09/02
- Re: [PATCH 3/3] telnet: Avoid command evaluation crashes., Simon Josefsson, 2022/09/02
- TFTP client crash seems to be caused by missing bounds check in makeargv(), Erik Auerswald, 2022/09/04
- Re: TFTP client crash seems to be caused by missing bounds check in makeargv(), Erik Auerswald, 2022/09/04
- Re: TFTP client crash seems to be caused by missing bounds check in makeargv(), Simon Josefsson, 2022/09/06
- Re: TFTP client crash seems to be caused by missing bounds check in makeargv(), Erik Auerswald, 2022/09/07
- Re: TFTP client crash seems to be caused by missing bounds check in makeargv(), Simon Josefsson, 2022/09/08
- How to check for perl or usable printf tools?, Erik Auerswald, 2022/09/11
- Re: How to check for perl or usable printf tools?, Simon Josefsson, 2022/09/12
- Re: How to check for perl or usable printf tools?, Alfred M. Szmidt, 2022/09/12