From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:55216) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d6TWM-0002d4-Bn for guix-patches@gnu.org; Thu, 04 May 2017 23:03:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d6TWI-0007Fh-Dm for guix-patches@gnu.org; Thu, 04 May 2017 23:03:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:56903) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1d6TWI-0007FW-8e for guix-patches@gnu.org; Thu, 04 May 2017 23:03:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1d6TWH-00040v-P4 for guix-patches@gnu.org; Thu, 04 May 2017 23:03:01 -0400 Subject: bug#26781: rpcbind, libtirpc CVE-2017-8779 Resent-Message-ID: From: Kei Kebreau References: <20170505013227.GA6479@jasmine> Date: Thu, 04 May 2017 23:02:22 -0400 In-Reply-To: <20170505013227.GA6479@jasmine> (Leo Famulari's message of "Thu, 4 May 2017 21:32:27 -0400") Message-ID: <87pofogg5d.fsf@openmailbox.org> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Leo Famulari Cc: 26781@debbugs.gnu.org --=-=-= Content-Type: text/plain Leo Famulari writes: > These patches update libtirpc and rpcbind to the latest release and fix > CVE-2017-8779 ("rpcbomb"). > > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779 > https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/ LGTM. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEg7ZwOtzKO2lLzi2m5qXuPBlGeg0FAlkL6z4ACgkQ5qXuPBlG eg07CQ//ThvWmQ17SrEdvw4uZg64SSwetqT2Hazl73GcXr5oi21FHI3cdFCekd6K 99RNDxDxpuxamTC+Jh0U3ey/OybCSqBvt7vA4FsyN/v7QThWidKvyCtnML6XLYzm 4wH0JytkRhc5TSydUh8CrrGJgLpae6M9aytZzPBbMygO5qa72L1vgOBD4lNzBOVH XgsCZEVFnoEC80hkXk69x01dJVxTH8J0YUr4WqpT/54ZDNq1WktinueiW1dr7ILc HgYGxg1EfmZVVhq2BaF4KJvZGKZJWD7WgCaPOe1+ITnSMfrnCi7GH6J37eXC/rP5 fwIhpNVbvyPPMhMlOas5Hg1J2/T0qFAy8TKuYcZN52Pqs9zUVSqQ0ofwwDcuQZPR lXpFPDCh+BzCHRdNbbsv9hNBfjgL69/FPXiTN1SDFbfn0JZhXNQ96qcTweXNFLkE lPE1Q9Ec9nJf9GNTewtxUf72cBNtP/ukTdQTez3JTIAXZqj7lpW+qmgqh9fYqWkc oD12MG7KuAG9HlOCNUe/TJHdRKKAS4T5FIRxQSTdKrQTGKbUw8L5XbdCiYShKNk4 372CBnsf7mnVhMQtntMLjYn3BJ+BR5L8wo2mXyRNFArw9D15IqaNi+7Fsk0q0Xsv vOMnXCkf3zc/9t9BpO08C8Bx2g/9g1ZWmOedESZEl7nS44yBpQQ= =x185 -----END PGP SIGNATURE----- --=-=-=--