Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 16 Jun 2012 19:35:37 -0600
From: Kurt Seifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
CC: Hanno Böck <hanno@...eck.de>
Subject: Re: CVE request: java hashdos vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 06/15/2012 03:13 PM, Hanno Böck wrote:
> Hi,
> 
> Seems java is fixing HashDos finally: 
> http://mail.openjdk.java.net/pipermail/core-libs-dev/2012-May/010238.html
>
>  They don't mention hashdos, but the interesting part is here: "The
> enhanced hashing implementation uses the murmur3 hashing 
> algorithm[1] along with random hash seeds and index masks"
> 
> random hash seeds is what prevents hashdos.
> 
> Further info here: 
> http://armoredbarista.blogspot.de/2012/02/investigating-hashdos-issue.html
>
>  Please assign CVE.
> 
> cu,

Please use CVE-2012-2739 for this issue.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJP3TRpAAoJEBYNRVNeJnmTxn0QAKxwvxvhuT1kRmfgIQBHCIIv
TbPsz7Ve53LbyT2tEXwWzEO406sUbtUK1rC6ziWkZraihCghkX7pYwG3CkFKRDcj
RCos6/THW6aJ1X3BIeOJnFYLPdX+ayEKa9lkVOBB8DChnNT6gDfCnWHwcr0K6nhs
hiwoofIjlbwA9HZnDGFt4INUv19Eo3AQ/q6j99N+o+nraRye/DUoYU+VZe4rLICQ
sCHdkKdGWp5889lItap19hWLTSWNjzkXIyZIcVAc7qw7NAApLVRrA7kCVOQHc4+4
YQTHy/6jaPdjFjwRNyKFczIq5i3BO9tcAr8SQrrjujImMCCDGwgk2k8Pti6KSAJE
9w1lL2uUHCKdRvheUZi2NppbMDnhlqtnugFDZdePHUp5JeAk2Er6fNIjH6r8LKym
3AuWhCRlxQ1aH0qcck8K/7CgcfzSLNixgDoU0OVmlmZ8qn/wp7bNddQKOyQ0A72q
VBnnD9qRQ8hx1ZL3keybUMP63yymOwlVHzb1cKJwbgiT21+Pr7mxekrPkmixPiah
Ac6LsMOiyU9N04aAed18N1CHcm5hfU+fKZGXn6J4HLzjTN4VYcitfE/qWYaJLuRm
6mvlpBEVMpgbteT3Rv2aJ7Bhhd1EQ/sbOMUbU7UH5/nX2ntt6PZ3ph4Gcx99ML68
VvgDhCr3p/bOQh8uFZZu
=3E+5
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.