cvs commit: src/sys/netinet6 in6_proto.c ip6_var.h route6.c
Matthew Dillon
dillon at crater.dragonflybsd.org
Wed Apr 25 14:56:29 PDT 2007
dillon 2007/04/25 14:55:33 PDT
DragonFly src repository
Modified files:
sys/netinet6 in6_proto.c ip6_var.h route6.c
Log:
IPV6 type 0 route headers are a flawed design, insecure by default, and
open hosts and networks up to DOS attacks by allowing normal router IP
filtering to be bypassed. Disable them by default.
Submitted-by: Hasso Tepper <hasso at estpak.ee>
Obtained-from: OpenBSD
Revision Changes Path
1.11 +3 -0 src/sys/netinet6/in6_proto.c
1.11 +1 -0 src/sys/netinet6/ip6_var.h
1.7 +27 -23 src/sys/netinet6/route6.c
http://www.dragonflybsd.org/cvsweb/src/sys/netinet6/in6_proto.c.diff?r1=1.10&r2=1.11&f=u
http://www.dragonflybsd.org/cvsweb/src/sys/netinet6/ip6_var.h.diff?r1=1.10&r2=1.11&f=u
http://www.dragonflybsd.org/cvsweb/src/sys/netinet6/route6.c.diff?r1=1.6&r2=1.7&f=u
More information about the Commits
mailing list