From owner-freebsd-bugbusters@FreeBSD.ORG Thu Feb 20 20:48:23 2014 Return-Path: Delivered-To: bugbusters@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 60F6A4FD for ; Thu, 20 Feb 2014 20:48:23 +0000 (UTC) Received: from mail-wg0-f44.google.com (mail-wg0-f44.google.com [74.125.82.44]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id E02391D58 for ; Thu, 20 Feb 2014 20:48:22 +0000 (UTC) Received: by mail-wg0-f44.google.com with SMTP id k14so1855366wgh.11 for ; Thu, 20 Feb 2014 12:48:15 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=Ww5UHXZgUJ5UlPE3BTFLM/FmV5vkDqkQ/r/55HmLH7w=; b=ClwSDxS/I+HNROwjMhsKq20GGFO5mhUfb96IKiy1p65KDtbcDTW7lh5FsN2vUJ/Y+M b5sKoyUyrHCqJf9F60CT4vyZ0qjjq9ZIcott/i0AZoV89IYq4Zl0dMKyuzc9iZHO7MoO q8yXUzbM4pGYP/4S60mRKepgVY8+K8zVDQQgz+hGyfAoSwP+f8oQEKjbHFo1+1iINzJz L5fTKLcZKG93dD6jb2mmJfIXm9Hm1bjk/O+AcTYTz3lx9rTTEXo8CG5XPT0m1x0RTf/t 2OUd8MdPx+KkA0q7FUWEnzNqvwqluafWtMpWwbAMR2P3nGX2Qaryy+bk3Xbs3V+/FLTh e5EQ== X-Gm-Message-State: ALoCoQlra36ainSAvYBPOqB30/SUwBV4MviFfSc597MFQpu/Ey95zu4IVZAOIIZ/03s0bbKvQFPk X-Received: by 10.194.108.41 with SMTP id hh9mr3871320wjb.89.1392928886776; Thu, 20 Feb 2014 12:41:26 -0800 (PST) MIME-Version: 1.0 Received: by 10.194.241.168 with HTTP; Thu, 20 Feb 2014 12:41:06 -0800 (PST) In-Reply-To: <87y51bwg4w.fsf@mid.deneb.enyo.de> References: <52FC1916.4060501@freeradius.org> <87sirkm8uo.fsf@mid.deneb.enyo.de> <52FFD55C.5030408@freeradius.org> <87y51bwg4w.fsf@mid.deneb.enyo.de> From: Pierre Carrier Date: Thu, 20 Feb 2014 12:41:06 -0800 Message-ID: Subject: Re: freeradius denial of service in authentication flow To: Florian Weimer Content-Type: text/plain; charset=UTF-8 Cc: secalert , pkgsrc-security , security@ubuntu.com, security@freeradius.org, Alan DeKok , pupykin.s+arch@gmail.com, security@debian.org, bugbusters X-BeenThere: freebsd-bugbusters@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: "Coordination of the Problem Report handling effort." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 20 Feb 2014 20:48:23 -0000 On Sun, Feb 16, 2014 at 1:39 AM, Florian Weimer wrote: > I will request a CVE on oss-security. Thanks. I'm gonna drop this thread as I don't expect to prioritize this issue much further. Everyone, feel free to reach out off thread if you need anything else from me. Best, -- Pierre Carrier