Bugtraq mailing list archives

Ip packet filtering with bridging on freebsd


From: Darren Reed <avalon () COOMBS ANU EDU AU>
Date: Tue, 1 Aug 2000 07:14:50 +1000

If someone is doing packet filtering using ipfw to do packet filtering
with a FreeBSD box configured to do bridging, it is relatively easy to
make the box go "boom" as none of the standard header sanity checks
are done prior to the filter routine being called (check /sys/net/bridge.c)
It is a feature "copied" from OpenBSD but somehow large amounts of code
were not copied and bugs resulted.


Current thread: