_
¯¯¯\__/ ༼ つ ◕_◕ ༽つ (ง'̀-'́)ง(╯°□°)╯︵ ┻━┻ ヽ(´ー`)ノ \__/¯¯
¯
Product: sipXcom sipXopenfire
Vendor: CoreDial
Name: "sipXcom sipXopenfire XMP
SEC Consult Vulnerability Lab Security Advisory < 20230306-0 >
===
title: Multiple Vulnerabilities
product: Arris DG3450 Cable Gateway
vulnerable version: AR01.02.056.18_041520_711.NCS.10
Hi,
Fun OpenBSD bug.
ip_dooptions() will allow IPOPT_SSRR with optlen = 2.
save_rte() will set isr_nhops to very large value, which will cause
overflow in next ip_srcroute() call.
More info is here https://github.com/fuzzingrf/openbsd_tcpip_overflow/
-erg