Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 15 Apr 2014 10:05:48 -0400 (EDT)
From: cve-assign@...re.org
To: marc.deslauriers@...onical.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE Request: rsync denial of service

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> rsync 3.1.0 contains a denial of service issue

> a remote client can send an invalid username and cause an infinite CPU
> loop on the server child process.
> 
> The server master process is unaffected, allowing the remote client to
> do this multiple times toward system-wide denial of service.

> Wayne Davison 2014-04-13 21:14:04 UTC
> 
> I've committed a fix for this into git for release in 3.1.1.

https://bugzilla.samba.org/show_bug.cgi?id=10551
https://bugs.launchpad.net/ubuntu/+source/rsync/+bug/1307230
https://git.samba.org/?p=rsync.git;a=commit;h=0dedfbce2c1b851684ba658861fe9d620636c56a

Use CVE-2014-2855.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTTTxZAAoJEKllVAevmvms0osIAISAV1FFI1QsgpIaAzizTP7I
JvnQ60EWLWlgHSAmTEEByU9GIzNIpgkccUt5MuTU55kbs/Twybxk1jBJwLbRv+57
lugTYi8gmKV26W1dnYY6gIEo3QyJNAXMK9I+4/fW8MSsPdkP3R7LumHagwoEryI5
vH1YVqwfFz49s9tQ3G2QY9i6B2gKEgPjmFo2n/K+UJAgD9rtqA8QCAGKd1XfdPPL
aG2Q2q31WfFw9w4fwDTEhY7s9Tn1Y+0f7HraJY9g6hqptSztxqH90wo9vzPthzs6
Io4MvYtwvQR725imLaSS51PiVYhqEBU22uV9fH8j/8NJvImmMNoFpelX4J1NBKY=
=U7Ut
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.