Malformed uncompressed packets may crash the ROHC compressor

Bug #1105935 reported by Didier Barvaux
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
rohc
Status tracked in Rohc-main
1.3.x
Fix Released
Critical
Didier Barvaux
1.4.x
Fix Released
Critical
Didier Barvaux
Rohc-1.5.x
Fix Released
Critical
Didier Barvaux
Rohc-main
Fix Released
Critical
Didier Barvaux

Bug Description

If some malformed (too short) IPv4, IPv6, IP/UDP, and IP/UDP/RTP packets are compressed with the ROHC library, the library might access some memory outside packet boundaries. This may cause the library to crash.

The attached capture contains:
 - one IPv4 packet with partial IPv4 header,
 - one IPv6 packet with partial IPv6 header,
 - one IPv4/UDP packet with partial UDP header,
 - one IPv4/UDP/RTP packet with partial RTP header.

Problem reported by Yura.

Revision history for this message
Didier Barvaux (didier-barvaux) wrote :
Revision history for this message
Didier Barvaux (didier-barvaux) wrote :
description: updated
Revision history for this message
Didier Barvaux (didier-barvaux) wrote :
Revision history for this message
Didier Barvaux (didier-barvaux) wrote :
Revision history for this message
Didier Barvaux (didier-barvaux) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.