Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 14 Jan 2014 15:53:08 -0800
From:      Gregory Shapiro <gshapiro@gshapiro.net>
To:        freebsd-security@freebsd.org
Subject:   Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-14:01.bsnmpd
Message-ID:  <20140114235308.GB13117@minime.us.proofpoint.com>
In-Reply-To: <201401142011.s0EKB8Zw082592@freefall.freebsd.org>
References:  <201401142011.s0EKB8Zw082592@freefall.freebsd.org>

index | next in thread | previous in thread | raw e-mail

> Topic:          bsnmpd remote denial of service vulnerability
...
> III. Impact
> 
> This issue could be exploited to execute arbitrary code in the context of
> the service daemon, or crash the service daemon, causing a denial-of-service.

The title/topic of this advisory should be changed reflect the more serious of these impacts, "execute arbitrary code".  IMHO, this is a much larger impact than bsnmpd crashing.


help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20140114235308.GB13117>