summaryrefslogtreecommitdiff
path: root/net/hostapd/files/patch-src_ap_wmm.c
diff options
context:
space:
mode:
authorJohn Marino <marino@FreeBSD.org>2015-06-02 09:52:01 +0000
committerJohn Marino <marino@FreeBSD.org>2015-06-02 09:52:01 +0000
commitdca0df99ed63762f428e4c8a05b82ebfd34b8dbf (patch)
tree0bfa254b981a09ed1e199afc9c15f2082225199e /net/hostapd/files/patch-src_ap_wmm.c
parentsecurity/vuxml: multiple vulnerabilities of wpa_supplicant and hostapd (diff)
net/hostapd: Address 3 latest security advisories
These are combined upstream patches 2015-2, 2015-3, 2015-4 They address the following security advisories: * CVE-2015-4141 * CVE-2015-4142 * CVE-2015-4143 * CVE-2015-4144 * CVE-2015-4145 * CVE-2015-4146 These advisories also apply to security/wpa_supplicant PR: 200567 Submitted by: Jason Unovitch Approved by: maintainer (Craig Leres)
Diffstat (limited to 'net/hostapd/files/patch-src_ap_wmm.c')
-rw-r--r--net/hostapd/files/patch-src_ap_wmm.c12
1 files changed, 12 insertions, 0 deletions
diff --git a/net/hostapd/files/patch-src_ap_wmm.c b/net/hostapd/files/patch-src_ap_wmm.c
new file mode 100644
index 000000000000..3da758573de3
--- /dev/null
+++ b/net/hostapd/files/patch-src_ap_wmm.c
@@ -0,0 +1,12 @@
+--- src/ap/wmm.c.orig 2015-03-15 17:30:39 UTC
++++ src/ap/wmm.c
+@@ -274,6 +274,9 @@ void hostapd_wmm_action(struct hostapd_d
+ return;
+ }
+
++ if (left < 0)
++ return; /* not a valid WMM Action frame */
++
+ /* extract the tspec info element */
+ if (ieee802_11_parse_elems(pos, left, &elems, 1) == ParseFailed) {
+ hostapd_logger(hapd, mgmt->sa, HOSTAPD_MODULE_IEEE80211,