Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] Re: Linux Kernel sctp_setsockopt() Integer Overflow |
|---|---|
| Date: | Sun, 16 May 2004 00:08:50 +0200 |
How did you come from the above snippet of the code to the idea that kmalloc(0) returns NULL?
Doesn't matter: the first thing linux's sys_setsockopt() does is checking if optlen is < 0. It will fail in this case. So the needed optlen is never handled down to the protocol setsockopt function. Otherwise you would find several protocol handlers vulnerable... f.e. IPv6... Stefan Esser -- -------------------------------------------------------------------------- Stefan Esser s.esser@e-matters.de e-matters Security http://security.e-matters.de/ GPG-Key gpg --keyserver pgp.mit.edu --recv-key 0xCF6CAE69 Key fingerprint B418 B290 ACC0 C8E5 8292 8B72 D6B0 7704 CF6C AE69 -------------------------------------------------------------------------- Did I help you? Consider a gift: http://wishlist.suspekt.org/ --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Vuln. MacOSX/Safari: Remote help-call, execute scripts, Troels Bay |
|---|---|
| Next by Date: | [Full-Disclosure] Re: lha buffer overflow(s) again, Ulf Härnhammar |
| Previous by Thread: | Re: [Full-Disclosure] Re: Linux Kernel sctp_setsockopt() Integer Overflow, Jirka Kosina |
| Next by Thread: | [Full-Disclosure] Re: Linux Kernel sctp_setsockopt() Integer Overflow, Evgeny Demidov |
| Indexes: | [Date] [Thread] [Top] [All Lists] |