Blame SOURCES/openssh-6.6p1-allow-ip-opts.patch

1d31ef
diff -up openssh/sshd.c.ip-opts openssh/sshd.c
1d31ef
--- openssh/sshd.c.ip-opts	2016-07-25 13:58:48.998507834 +0200
1d31ef
+++ openssh/sshd.c	2016-07-25 14:01:28.346469878 +0200
1d31ef
@@ -1507,12 +1507,29 @@ check_ip_options(struct ssh *ssh)
1d31ef
 
1d31ef
 	if (getsockopt(sock_in, IPPROTO_IP, IP_OPTIONS, opts,
f09e2e
 	    &option_size) >= 0 && option_size != 0) {
f09e2e
-		text[0] = '\0';
f09e2e
-		for (i = 0; i < option_size; i++)
f09e2e
-			snprintf(text + i*3, sizeof(text) - i*3,
1d31ef
-			    " %2.2x", opts[i]);
1d31ef
-		fatal("Connection from %.100s port %d with IP opts: %.800s",
1d31ef
-		    ssh_remote_ipaddr(ssh), ssh_remote_port(ssh), text);
f09e2e
+		i = 0;
f09e2e
+		do {
1d31ef
+			switch (opts[i]) {
f09e2e
+				case 0:
f09e2e
+				case 1:
f09e2e
+					++i;
f09e2e
+					break;
017ff1
+				case 130:
017ff1
+				case 133:
017ff1
+				case 134:
1d31ef
+					i += opts[i + 1];
017ff1
+					break;
017ff1
+				default:
f09e2e
+				/* Fail, fatally, if we detect either loose or strict
f09e2e
+			 	 * source routing options. */
f09e2e
+					text[0] = '\0';
f09e2e
+					for (i = 0; i < option_size; i++)
f09e2e
+						snprintf(text + i*3, sizeof(text) - i*3,
1d31ef
+							" %2.2x", opts[i]);
1d31ef
+					fatal("Connection from %.100s port %d with IP options:%.800s",
1d31ef
+						ssh_remote_ipaddr(ssh), ssh_remote_port(ssh), text);
f09e2e
+			}
f09e2e
+		} while (i < option_size);
f09e2e
 	}
1d31ef
 	return;
f09e2e
 #endif /* IP_OPTIONS */