Guy Harris wrote:

- while (length >= 2) {
+ while (length >= 2 && *data) {



"Termination" in what sense? RFC 2865 says


String

     The String field is one or more octets.  The actual format of the
     information is site or application specific, and a robust
     implementation SHOULD support the field as undistinguished octets.
     [...]

Is there something that indicates that a vendor type value of 0
terminates the sequence?


Ok, I might be wrong with my 0 termination approach. Anyway
there should be some kind of boundary check for 'data'.

--
Key fingerprint = 2A55 EB7C B7EA 6336 7767  4A47 910A 307B 1333 BD6C

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]

Reply via email to