commons-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Sebb (Commented) (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (NET-414) Apache Commons TFTP does not reject request replies that originate from a control port.
Date Tue, 10 Jan 2012 19:33:39 GMT

    [ https://issues.apache.org/jira/browse/NET-414?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13183503#comment-13183503
] 

Sebb commented on NET-414:
--------------------------

I'm not quite clear what code changes are needed here - have you a suggested patch?
                
> Apache Commons TFTP does not reject request replies that originate from a control port.
> ---------------------------------------------------------------------------------------
>
>                 Key: NET-414
>                 URL: https://issues.apache.org/jira/browse/NET-414
>             Project: Commons Net
>          Issue Type: Bug
>          Components: TFTP
>    Affects Versions: 2.2, 3.0
>         Environment: Java 1.6 Patch 20
>            Reporter: Chuck Wolber
>            Priority: Minor
>
> When a TFTP request response arrives that incorrectly specifies its source port as the
control port, the request should be rejected with an error code 5 (TFTPErrorPacket.UNKNOWN_TID)
and suggested text "INCORRECT SOURCE PORT". 
> This can happen when an incorrectly written TFTP server replies to a request from a control
socket instead of building a new socket that attaches to an ephemeral port.
> Note 1: The expected response from a read request is a DATA packet. The expected response
from a write request is an ACK packet.
> Note 2: The control port is implementation specific and not always port 69 (as defined
by IANA).

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Mime
View raw message