emacs-bug-tracker
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[debbugs-tracker] bug#26781: closed (rpcbind, libtirpc CVE-2017-8779)


From: GNU bug Tracking System
Subject: [debbugs-tracker] bug#26781: closed (rpcbind, libtirpc CVE-2017-8779)
Date: Fri, 05 May 2017 19:36:02 +0000

Your message dated Fri, 5 May 2017 15:35:56 -0400
with message-id <address@hidden>
and subject line Re: bug#26781: rpcbind, libtirpc CVE-2017-8779
has caused the debbugs.gnu.org bug report #26781,
regarding rpcbind, libtirpc CVE-2017-8779
to be marked as done.

(If you believe you have received this mail in error, please contact
address@hidden)


-- 
26781: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=26781
GNU Bug Tracking System
Contact address@hidden with problems
--- Begin Message --- Subject: rpcbind, libtirpc CVE-2017-8779 Date: Thu, 4 May 2017 21:32:27 -0400 User-agent: Mutt/1.8.2 (2017-04-18)
These patches update libtirpc and rpcbind to the latest release and fix
CVE-2017-8779 ("rpcbomb").

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779
https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/

Attachment: 0001-gnu-rpcbind-Update-to-0.2.4.patch
Description: Text document

Attachment: 0002-gnu-libtirpc-Update-to-1.0.1.patch
Description: Text document

Attachment: 0003-gnu-rpcbind-libtirpc-Fix-CVE-2017-8779.patch
Description: Text document

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message --- Subject: Re: bug#26781: rpcbind, libtirpc CVE-2017-8779 Date: Fri, 5 May 2017 15:35:56 -0400 User-agent: Mutt/1.8.2 (2017-04-18)
On Fri, May 05, 2017 at 09:56:44AM +0200, Ludovic Court├Ęs wrote:
> Leo Famulari <address@hidden> skribis:
> 
> > These patches update libtirpc and rpcbind to the latest release and fix
> > CVE-2017-8779 ("rpcbomb").
> >
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779
> > https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
> 
> Excellent.  The 3 patches LGTM.
> 
> Thank you Leo!

Thanks for the reviews! Pushed!

I sent a followup patch to update nfs-utils. Somebody who uses NFS
should review it.

Attachment: signature.asc
Description: PGP signature


--- End Message ---

reply via email to

[Prev in Thread] Current Thread [Next in Thread]