Subject: Re: [PATCH] Security: Validate response address, possibly related to CVE-2008-1447

Re: [PATCH] Security: Validate response address, possibly related to CVE-2008-1447

From: Yang Tse <yangsita_at_gmail.com>
Date: Thu, 21 Aug 2008 04:13:50 +0200

Hi Brad,

2008/8/19, Brad House wrote:

> Yeah, he changed some header stuff and partially committed it...
> I've updated the patch for the current CVS HEAD, it is attached.
> Not sure why the rest wasn't committed, or what concerns he may
> have had...

Ah, well, lets see...

An initial effort for a proper 'sreadfrom' macro was done. it outcomed
that there is much more work involved than I initially estimated (HPUX
main culprit). And as I already had something 'more time consuming'
that should be completed before next libcurl release release (the
curl_off_t stuff) I simply left the sreadfrom macro definition in the
source tree 'as is' but didn't actually use it in the source tree.

So, sorry for not getting back to you on this.

Could you simply use recvfrom in your patch and get rid of the sreadfrom usage ?

That way everything should work.

-- 
-=[Yang]=-
Received on 2008-08-21