commit | 71ffe9c77dd7a2b62207953091efa8dafec958dd | [log] [tgz] |
---|---|---|
author | Pablo Neira Ayuso <pablo@netfilter.org> | Thu Jul 25 10:37:49 2013 +0200 |
committer | Pablo Neira Ayuso <pablo@netfilter.org> | Thu Aug 01 11:42:53 2013 +0200 |
tree | d0251ec9b294378915562e50a62ae095616d5430 | |
parent | a661b43fd047ef501da43a19975415f861c7c3db [diff] |
netfilter: xt_TCPMSS: fix handling of malformed TCP header and options Make sure the packet has enough room for the TCP header and that it is not malformed. While at it, store tcph->doff*4 in a variable, as it is used several times. This patch also fixes a possible off by one in case of malformed TCP options. Reported-by: Julian Anastasov <ja@ssi.bg> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>