GNU bug report logs - #26781
rpcbind, libtirpc CVE-2017-8779

Previous Next

Package: guix-patches;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Fri, 5 May 2017 01:33:02 UTC

Severity: normal

Done: Leo Famulari <leo <at> famulari.name>

Bug is archived. No further changes may be made.

Full log


Message #11 received at 26781 <at> debbugs.gnu.org (full text, mbox):

From: ludo <at> gnu.org (Ludovic Courtès)
To: Leo Famulari <leo <at> famulari.name>
Cc: 26781 <at> debbugs.gnu.org
Subject: Re: bug#26781: rpcbind, libtirpc CVE-2017-8779
Date: Fri, 05 May 2017 09:56:44 +0200
Leo Famulari <leo <at> famulari.name> skribis:

> These patches update libtirpc and rpcbind to the latest release and fix
> CVE-2017-8779 ("rpcbomb").
>
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779
> https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/

Excellent.  The 3 patches LGTM.

Thank you Leo!

Ludo’.




This bug report was last modified 8 years and 109 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.