Commit Graph

7 Commits

Author SHA1 Message Date
Paul Mackerras
6131dfddd8
pppd: Ignore received EAP messages when not doing EAP
This adds some basic checks to the subroutines of eap_input to check
that we have requested or agreed to doing EAP authentication before
doing any processing on the received packet.  The motivation is to
make it harder for a malicious peer to disrupt the operation of pppd
by sending unsolicited EAP packets.  Note that eap_success() already
has a check that the EAP client state is reasonable, and does nothing
(apart from possibly printing a debug message) if not.

Signed-off-by: Paul Mackerras <paulus@ozlabs.org>
2020-10-29 00:18:01 +01:00
Marek Kraus
d54b64bd30 Merging with upstream 2020-10-28 23:31:02 +01:00
Marek Kraus
328c0609b7
Merge pull request #20 from ProZsolt/remove-esp32-references
Remove references for ESP32
2020-10-28 23:03:31 +01:00
Josef Schlehofer
87970e63c5
Fix buffer overflow in EAP
Fixes CVE-2020-8597
2020-10-28 19:41:15 +01:00
Zsolt Prontvai
3572e01f74 Remove references for ESP32 2020-10-28 17:46:37 +00:00
Jesus Velazquez
143f051b9c web_server.c: remove references to ESP32
Signed-off-by: Jesus Velazquez <jesus.velazquez@gmail.com>
2020-10-28 08:03:53 -07:00
Rujun Wang
ee4a10b1a1 Initial Commit 2020-10-26 20:35:25 +08:00