1
0
Fork 0
alistair23-linux/include/net/phonet
Dan Carpenter facb4edc1e phonet: some signedness bugs
Dan Rosenberg pointed out that there were some signed comparison bugs
in the phonet protocol.

http://marc.info/?l=full-disclosure&m=129424528425330&w=2

The problem is that we check for array overflows but "protocol" is
signed and we don't check for array underflows.  If you have already
have CAP_SYS_ADMIN then you could use the bugs to get root, or someone
could cause an oops by mistake.

Signed-off-by: Dan Carpenter <error27@gmail.com>
Acked-by: RĂ©mi Denis-Courmont <remi.denis-courmont@nokia.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2011-01-10 13:33:17 -08:00
..
gprs.h Phonet: implement GPRS virtual interface over PEP socket 2008-10-05 11:16:16 -07:00
pep.h Phonet: 'connect' socket implementation for Pipe controller 2010-10-13 14:40:34 -07:00
phonet.h phonet: some signedness bugs 2011-01-10 13:33:17 -08:00
pn_dev.h Phonet: list subscribed resources via proc_fs 2010-09-15 21:31:33 -07:00