Subject: kern/5660: IP Filter 3.2.9 should be imported in the tree
To: None <gnats-bugs@gnats.netbsd.org>
From: Klaus Weber <gizmo@zork.north.de>
List: netbsd-bugs
Date: 06/26/1998 16:40:17
>Number:         5660
>Category:       kern
>Synopsis:       IP Filter 3.2.9 fixes a serious problem
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people (Kernel Bug People)
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Fri Jun 26 07:50:01 1998
>Last-Modified:
>Originator:     Klaus Weber
>Organization:
	none
>Release:        1.3.2
>Environment:
	
System: NetBSD zork.north.de 1.3.2 NetBSD 1.3.2 (ZORK) #0: Thu Jun 25 19:14:29 CEST 1998 gizmo@zork.north.de:/usr/src/sys/arch/i386/compile/ZORK i386


>Description:
IP Filter versions before 3.2.9 incorrectly blocks the second and 
following fragment of fragmented IP packets. IP Filter 3.2.9 fixes
this problem, so it should be imported.

I think it should also be pulled up for the next bugfix-release, if any.

>How-To-Repeat:
Use IP Filter in NetBSD 1.3.2. Note incorrectly blocked fragments. 
Install IP Filter 3.2.9. Problem is gone.

>Fix:
	import IP Filter 3.2.9
>Audit-Trail:
>Unformatted: