guix-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#26781: rpcbind, libtirpc CVE-2017-8779


From: Leo Famulari
Subject: bug#26781: rpcbind, libtirpc CVE-2017-8779
Date: Fri, 5 May 2017 15:35:56 -0400
User-agent: Mutt/1.8.2 (2017-04-18)

On Fri, May 05, 2017 at 09:56:44AM +0200, Ludovic Courtès wrote:
> Leo Famulari <address@hidden> skribis:
> 
> > These patches update libtirpc and rpcbind to the latest release and fix
> > CVE-2017-8779 ("rpcbomb").
> >
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779
> > https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
> 
> Excellent.  The 3 patches LGTM.
> 
> Thank you Leo!

Thanks for the reviews! Pushed!

I sent a followup patch to update nfs-utils. Somebody who uses NFS
should review it.

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]