Skip to content

Commit

Permalink
WIP: initial security considerations
Browse files Browse the repository at this point in the history
  • Loading branch information
mcr committed Aug 16, 2024
1 parent 53eb940 commit 0edf5b0
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions draft-ietf-opsawg-pcaplinktype.md
Original file line number Diff line number Diff line change
Expand Up @@ -753,6 +753,16 @@ Linktypes may be allocated for specifications not publically available may be ma
This includes specifications that might be classified.
The minimal requirement is for a contact person for that link type.

# Security Considerations

This document describes the IANA registration rules for the LINKTYPE encapsulations.
PCAP, and PCAPNG packet file formats use this value to determine what kind of headers preceed network packet captures.
Many of these formats can contain IPv4 and IPv6 packets.
A system reading PCAP or PCAPNG format captures can be subject to arbitrary inputs that may be controlled by malicious entities, so utmost caution is required.

Many LINKTYPE formats include a "snapshot" length, which may be smaller than the actual packet. It is therefore very likely that trailing parts of a packet capture may be omitted, yet internal length fields in the packets will claim the packet is bigger than the capture.
This leads to trivial buffer overreads, and systems interpreting the packets need to carefully scrutinize all attempts to read data from a capture.


# Contributors

Expand Down

0 comments on commit 0edf5b0

Please sign in to comment.