diff options
| author | Martin Willi <martin@revosec.ch> | 2015-02-03 16:40:14 +0100 |
|---|---|---|
| committer | Martin Willi <martin@revosec.ch> | 2015-03-18 13:33:25 +0100 |
| commit | 84738b1aed955662106b272169915928e1232086 (patch) | |
| tree | aed513e7bba38359ed9a7033660827875b058da5 /src/libcharon/plugins/eap_dynamic | |
| parent | b8ecdfd8952d4c9021db565f22adb87a9adaa8b0 (diff) | |
| download | strongswan-84738b1aed95.tar.bz2 strongswan-84738b1aed95.tar.xz | |
encoding: Verify the length of KE payload data for known groups
IKE is very strict in the length of KE payloads, and it should be safe to
strictly verify their length. Not doing so is no direct threat, but allows DDoS
amplification by sending short KE payloads for large groups using the target
as the source address.
Diffstat (limited to 'src/libcharon/plugins/eap_dynamic')
0 files changed, 0 insertions, 0 deletions
