1. 16 May, 2015 1 commit
    • Simon Kelley's avatar
      Fix buffer overflow introduced in 2.73rc6. · 5d07d77e
      Simon Kelley authored
      Fix off-by-one in code which checks for over-long domain names
      in received DNS packets. This enables buffer overflow attacks
      which can certainly crash dnsmasq and may allow for arbitrary
      code execution. The problem was introduced in commit b8f16556,
      release 2.73rc6, so has not escaped into any stable release.
      Note that the off-by-one was in the label length determination,
      so the buffer can be overflowed by as many bytes as there are
      labels in the name - ie, many.
      
      Thanks to Ron Bowes, who used lcmatuf's afl-fuzz tool to find
      the problem.
      5d07d77e
  2. 15 May, 2015 2 commits
  3. 14 May, 2015 1 commit
  4. 13 May, 2015 2 commits
  5. 10 May, 2015 1 commit
  6. 09 May, 2015 1 commit
  7. 08 May, 2015 1 commit
  8. 29 Apr, 2015 3 commits
  9. 27 Apr, 2015 1 commit
  10. 26 Apr, 2015 1 commit
  11. 23 Apr, 2015 1 commit
  12. 22 Apr, 2015 1 commit
  13. 21 Apr, 2015 1 commit
  14. 20 Apr, 2015 1 commit
  15. 18 Apr, 2015 1 commit
  16. 16 Apr, 2015 3 commits
  17. 13 Apr, 2015 1 commit
  18. 10 Apr, 2015 1 commit
  19. 07 Apr, 2015 1 commit
  20. 04 Apr, 2015 2 commits
  21. 02 Apr, 2015 1 commit
  22. 01 Apr, 2015 1 commit
  23. 30 Mar, 2015 3 commits
  24. 29 Mar, 2015 1 commit
  25. 27 Mar, 2015 3 commits
  26. 20 Mar, 2015 2 commits
  27. 12 Mar, 2015 1 commit
  28. 08 Mar, 2015 1 commit