3161ff3
diff -up dhcp-4.1.0/client/dhclient.c.validate dhcp-4.1.0/client/dhclient.c
3161ff3
--- dhcp-4.1.0/client/dhclient.c.validate	2009-01-06 12:11:44.000000000 -1000
3161ff3
+++ dhcp-4.1.0/client/dhclient.c	2009-01-06 12:25:06.000000000 -1000
3161ff3
@@ -190,7 +190,7 @@ main(int argc, char **argv) {
3161ff3
 		} else if (!strcmp(argv[i], "-p")) {
4d127d8
 			if (++i == argc)
3161ff3
 				usage();
3161ff3
-			local_port = htons(atoi(argv[i]));
4d127d8
+			local_port = validate_port(argv[i]);
3161ff3
 			log_debug("binding to user-specified port %d",
3161ff3
 				  ntohs(local_port));
3161ff3
 		} else if (!strcmp(argv[i], "-d")) {
3161ff3
diff -up dhcp-4.1.0/common/inet.c.validate dhcp-4.1.0/common/inet.c
3161ff3
--- dhcp-4.1.0/common/inet.c.validate	2007-07-12 20:43:41.000000000 -1000
3161ff3
+++ dhcp-4.1.0/common/inet.c	2009-01-06 12:11:44.000000000 -1000
7abc547
@@ -604,3 +604,20 @@ piaddrcidr(const struct iaddr *addr, uns
4d127d8
 	return ret;
4d127d8
 }
7abc547
 
4d127d8
+/* Check the port number specified */
4d127d8
+u_int16_t
4d127d8
+validate_port(char *port) {
4d127d8
+	u_int16_t local_port = 0;
4d127d8
+	int lower = 1;
4d127d8
+	int upper = 65535;
4d127d8
+
4d127d8
+	errno = 0;
4d127d8
+	local_port = strtol(port, NULL, 10);
4d127d8
+	if ((errno == ERANGE) || (errno == EINVAL))
4d127d8
+		log_fatal ("Invalid port number specification: %s", port);
4d127d8
+
4d127d8
+	if (local_port < lower || local_port > upper)
4d127d8
+		log_fatal("Port number specified is out of range (%d-%d).", lower, upper);
4d127d8
+
4d127d8
+	return htons(local_port);
4d127d8
+}
3161ff3
diff -up dhcp-4.1.0/includes/dhcpd.h.validate dhcp-4.1.0/includes/dhcpd.h
3161ff3
--- dhcp-4.1.0/includes/dhcpd.h.validate	2009-01-06 12:11:43.000000000 -1000
3161ff3
+++ dhcp-4.1.0/includes/dhcpd.h	2009-01-06 12:11:44.000000000 -1000
3161ff3
@@ -65,6 +65,7 @@
6e6a8e9
 #endif
4d127d8
 
6e6a8e9
 #include <setjmp.h>
6e6a8e9
+#include <errno.h>
6e6a8e9
 
6e6a8e9
 #include "cdefs.h"
6e6a8e9
 #include "osdep.h"
3161ff3
@@ -2511,6 +2512,7 @@ isc_result_t free_iaddrcidrnetlist(struc
91cda35
 const char *piaddr PROTO ((struct iaddr));
91cda35
 char *piaddrmask(struct iaddr *, struct iaddr *);
91cda35
 char *piaddrcidr(const struct iaddr *, unsigned int);
91cda35
+u_int16_t validate_port(char *port);
91cda35
 
91cda35
 /* dhclient.c */
91cda35
 extern int nowait;
3161ff3
diff -up dhcp-4.1.0/relay/dhcrelay.c.validate dhcp-4.1.0/relay/dhcrelay.c
3161ff3
--- dhcp-4.1.0/relay/dhcrelay.c.validate	2009-01-06 12:11:43.000000000 -1000
3161ff3
+++ dhcp-4.1.0/relay/dhcrelay.c	2009-01-06 12:23:29.000000000 -1000
3161ff3
@@ -222,7 +222,7 @@ main(int argc, char **argv) {
3161ff3
 		} else if (!strcmp(argv[i], "-p")) {
4d127d8
 			if (++i == argc)
3161ff3
 				usage();
3161ff3
-			local_port = htons(atoi (argv[i]));
4d127d8
+			local_port = validate_port(argv[i]);
3161ff3
 			log_debug("binding to user-specified port %d",
3161ff3
 				  ntohs(local_port));
3161ff3
 		} else if (!strcmp(argv[i], "-c")) {
3161ff3
diff -up dhcp-4.1.0/server/dhcpd.c.validate dhcp-4.1.0/server/dhcpd.c
3161ff3
--- dhcp-4.1.0/server/dhcpd.c.validate	2009-01-06 12:11:43.000000000 -1000
3161ff3
+++ dhcp-4.1.0/server/dhcpd.c	2009-01-06 12:11:44.000000000 -1000
3161ff3
@@ -298,15 +298,7 @@ main(int argc, char **argv) {
4d127d8
 		if (!strcmp (argv [i], "-p")) {
4d127d8
 			if (++i == argc)
4d127d8
 				usage ();
4d127d8
-			for (s = argv [i]; *s; s++)
4d127d8
-				if (!isdigit ((unsigned char)*s))
4d127d8
-					log_fatal ("%s: not a valid UDP port",
4d127d8
-					       argv [i]);
4d127d8
-			status = atoi (argv [i]);
4d127d8
-			if (status < 1 || status > 65535)
4d127d8
-				log_fatal ("%s: not a valid UDP port",
4d127d8
-				       argv [i]);
4d127d8
-			local_port = htons (status);
4d127d8
+			local_port = validate_port(argv[i]);
4d127d8
 			log_debug ("binding to user-specified port %d",
4d127d8
 			       ntohs (local_port));
4d127d8
 		} else if (!strcmp (argv [i], "-f")) {
3161ff3
@@ -531,7 +523,7 @@ main(int argc, char **argv) {
4d127d8
 	if (!local_port)
4d127d8
 	{
4d127d8
 		if ((s = getenv ("DHCPD_PORT"))) {
4d127d8
-			local_port = htons (atoi (s));
4d127d8
+			local_port = validate_port(s);
4d127d8
 			log_debug ("binding to environment-specified port %d",
4d127d8
 				   ntohs (local_port));
4d127d8
 		} else {