Tags: kame/kame
Tags
added stricter validation on source address (for reference purpose only)
(forced commit to update the commit log of rev 1.37) the diff was taken from FreeBSD's rev 1.7.4.1.4.1 of ipcomp_input.c (which was then incorporated to NetBSD, whose rev is 1.28).
merbed back a fix to invalid pointer access (FreeBSD's rev 1.28 of ipcomp_input.c)
fix problems with the previous commit. verified compilation on openbsd 4.1-current.
RFC3946 (by pekka savola) has all the details on 6to4 packet filtering.
refer draft-{itojun,cmetz}-*-harmful*.txt and
draft-ietf-v6ops-security-overview-06.txt (again, by pekka savola).
PreviousNext