|
Message-Id: <201404151405.s3FE5mVW020157@linus.mitre.org> Date: Tue, 15 Apr 2014 10:05:48 -0400 (EDT) From: cve-assign@...re.org To: marc.deslauriers@...onical.com Cc: cve-assign@...re.org, oss-security@...ts.openwall.com Subject: Re: CVE Request: rsync denial of service -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > rsync 3.1.0 contains a denial of service issue > a remote client can send an invalid username and cause an infinite CPU > loop on the server child process. > > The server master process is unaffected, allowing the remote client to > do this multiple times toward system-wide denial of service. > Wayne Davison 2014-04-13 21:14:04 UTC > > I've committed a fix for this into git for release in 3.1.1. https://bugzilla.samba.org/show_bug.cgi?id=10551 https://bugs.launchpad.net/ubuntu/+source/rsync/+bug/1307230 https://git.samba.org/?p=rsync.git;a=commit;h=0dedfbce2c1b851684ba658861fe9d620636c56a Use CVE-2014-2855. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJTTTxZAAoJEKllVAevmvms0osIAISAV1FFI1QsgpIaAzizTP7I JvnQ60EWLWlgHSAmTEEByU9GIzNIpgkccUt5MuTU55kbs/Twybxk1jBJwLbRv+57 lugTYi8gmKV26W1dnYY6gIEo3QyJNAXMK9I+4/fW8MSsPdkP3R7LumHagwoEryI5 vH1YVqwfFz49s9tQ3G2QY9i6B2gKEgPjmFo2n/K+UJAgD9rtqA8QCAGKd1XfdPPL aG2Q2q31WfFw9w4fwDTEhY7s9Tn1Y+0f7HraJY9g6hqptSztxqH90wo9vzPthzs6 Io4MvYtwvQR725imLaSS51PiVYhqEBU22uV9fH8j/8NJvImmMNoFpelX4J1NBKY= =U7Ut -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.