oss-sec mailing list archives

Re: cups-browsed vulnerable to DDoS amplification attack


From: Larry Cashdollar <larry0 () me com>
Date: Thu, 3 Oct 2024 19:14:35 +0000 (UTC)

Hello, Peter On Oct 3, 2024, at 2:58 PM, Peter van Dijk <peter () 7bits nl> wrote: Hello, On Thu, Oct 3, 2024, at 19:54, Larry 
Cashdollar wrote: I've requested a CVE ID to be able to discern between the RCE and the DoS vulnerability. I reported this as 
https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq86-c7g6-r2h8 last week, and in the edits at the top (by upstream, 
above the Summary heading) it looks like they did not want (or did not consider) to request a separate CVE for this. Please do coordinate 
with them if you decide to go ahead with this request. (I did notice, and can see value in, Will Dormann's suggestion in the other 
thread that it might make sense to have more fine-grained CVEs for this collection of problems.) -- Peter van Dijk peter () 7bits nl 
I'll follow up with them. Thanks! Larry

Current thread: