Skip to content
  • Shawn Routhier's avatar
    Previously the server code was relaxed to allow packets with zero · cd393f0d
    Shawn Routhier authored
    length client ids to be processed.  Under some situations use of
    zero length client ids can cause the server to go into an infinite
    loop.  As such ids are not valid according to RFC 2132 section 9.14
    the server no longer accepts them.  Client ids with a length of 1
    are also invalid but the server still accepts them in order to
    minimize disruption.  The restriction will likely be tightened in
    the future to disallow ids with a length of 1.
    Thanks to Markus Hietava of Codenomicon CROSS project for the
    finding this issue and CERT-FI for vulnerability coordination.
    [ISC-Bugs #29851]
    CVE: CVE-2012-3571
    cd393f0d