mirror of
http://thekelleys.org.uk/git/dnsmasq.git
synced 2026-10-08 07:54:32 +07:00
83658efbf4ba0d313e8e9628fa6f8e7d4f0944cf
Commit 3e659bd4ec removed the concept of
an usptream DNS server which is capable of DNSSEC: they are all
(at least in theory) now usable. As a very unfortunate side-effect,
this removed the filter that ensured that dnssec_server() ONLY
returns servers, and not domains with literal addresses.
If we try and do DNSSEC queries for a domain, and there's
a --address line which matches the domain, then dnssec_server()
will return that. This would break DNSSEC validation, but that's
turns out not to matter, because under these circumstances
dnssec_server() will probably return an out-of-bounds index into
the servers[] array, and the process dies with SIGSEGV.
Many thanks to the hard workers at the Tomato project who
found this bug and provided enough information to diagnose it.
…
…
Description
No description provided
12 MiB
Languages
C
94.3%
Perl
2.2%
HTML
1.2%
Shell
1%
Makefile
0.6%
Other
0.6%