From owner-freebsd-bugs@FreeBSD.ORG Wed Nov 24 00:47:18 2004 Return-Path: Delivered-To: freebsd-bugs@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9F61F16A4CE for ; Wed, 24 Nov 2004 00:47:18 +0000 (GMT) Received: from rproxy.gmail.com (rproxy.gmail.com [64.233.170.203]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2F56643D41 for ; Wed, 24 Nov 2004 00:47:18 +0000 (GMT) (envelope-from phil.brennan@gmail.com) Received: by rproxy.gmail.com with SMTP id 34so16112rns for ; Tue, 23 Nov 2004 16:47:17 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=KrAGYDdS4qj3gcJFufOkcHHJO2AdNDEo0JuPWFuv9nVjhUYeuXAfitFn87PqL24KqPMPRXzuq0tQD2TVZ2epRqrseJxx823bzxaFVEBIey8PtqF4U+WxAoNrfqvQRPLFQk7OrhR9t3/VOclnAYuvlYM7RT7T1moqn+J1f/MA2AE= Received: by 10.38.8.74 with SMTP id 74mr72397rnh; Tue, 23 Nov 2004 16:47:17 -0800 (PST) Received: by 10.38.179.54 with HTTP; Tue, 23 Nov 2004 16:47:17 -0800 (PST) Message-ID: Date: Wed, 24 Nov 2004 00:47:17 +0000 From: Phil Brennan To: Robert Watson In-Reply-To: Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit References: cc: freebsd-bugs@freebsd.org Subject: Re: bin/61084: nfsd sometimes exits prematurely during port-scan X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Phil Brennan List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 24 Nov 2004 00:47:18 -0000 Its a university networking society machine, so it wasn't the end of the world ( no money was lost :) ). Gonna try and use it as an example of how to trace a problem in our admin training. Thanks again. On Tue, 23 Nov 2004 23:43:46 +0000 (GMT), Robert Watson wrote: > On Tue, 23 Nov 2004, Phil Brennan wrote: > > > > > The fix for this has not been committed to RELENG_5_2. > > src/usr.sbin/nfsd/nfsd.c is still at 1.28, when it should be 1.29. This > > is very unfortunate, as it allows a denial of service simply by running > > nmap against the box. Could this be committed to this branch also, as > > there are quite a lot of people still running 5.2.1. Thanks. ( Just got > > bitten by this today ) Regards, > > I'll put in a request to the re@ team to get this merged ASAP. Thanks for > the pointer, and sorry about not having merged it there previously! > > Robert N M Watson FreeBSD Core Team, TrustedBSD Projects > robert@fledge.watson.org Principal Research Scientist, McAfee Research > >