|
Message-ID: <4FDD3469.8030404@redhat.com> Date: Sat, 16 Jun 2012 19:35:37 -0600 From: Kurt Seifried <kseifried@...hat.com> To: oss-security@...ts.openwall.com CC: Hanno Böck <hanno@...eck.de> Subject: Re: CVE request: java hashdos vulnerability -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 06/15/2012 03:13 PM, Hanno Böck wrote: > Hi, > > Seems java is fixing HashDos finally: > http://mail.openjdk.java.net/pipermail/core-libs-dev/2012-May/010238.html > > They don't mention hashdos, but the interesting part is here: "The > enhanced hashing implementation uses the murmur3 hashing > algorithm[1] along with random hash seeds and index masks" > > random hash seeds is what prevents hashdos. > > Further info here: > http://armoredbarista.blogspot.de/2012/02/investigating-hashdos-issue.html > > Please assign CVE. > > cu, Please use CVE-2012-2739 for this issue. - -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQIcBAEBAgAGBQJP3TRpAAoJEBYNRVNeJnmTxn0QAKxwvxvhuT1kRmfgIQBHCIIv TbPsz7Ve53LbyT2tEXwWzEO406sUbtUK1rC6ziWkZraihCghkX7pYwG3CkFKRDcj RCos6/THW6aJ1X3BIeOJnFYLPdX+ayEKa9lkVOBB8DChnNT6gDfCnWHwcr0K6nhs hiwoofIjlbwA9HZnDGFt4INUv19Eo3AQ/q6j99N+o+nraRye/DUoYU+VZe4rLICQ sCHdkKdGWp5889lItap19hWLTSWNjzkXIyZIcVAc7qw7NAApLVRrA7kCVOQHc4+4 YQTHy/6jaPdjFjwRNyKFczIq5i3BO9tcAr8SQrrjujImMCCDGwgk2k8Pti6KSAJE 9w1lL2uUHCKdRvheUZi2NppbMDnhlqtnugFDZdePHUp5JeAk2Er6fNIjH6r8LKym 3AuWhCRlxQ1aH0qcck8K/7CgcfzSLNixgDoU0OVmlmZ8qn/wp7bNddQKOyQ0A72q VBnnD9qRQ8hx1ZL3keybUMP63yymOwlVHzb1cKJwbgiT21+Pr7mxekrPkmixPiah Ac6LsMOiyU9N04aAed18N1CHcm5hfU+fKZGXn6J4HLzjTN4VYcitfE/qWYaJLuRm 6mvlpBEVMpgbteT3Rv2aJ7Bhhd1EQ/sbOMUbU7UH5/nX2ntt6PZ3ph4Gcx99ML68 VvgDhCr3p/bOQh8uFZZu =3E+5 -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.