oss-sec mailing list archives
Re[2]: cups-browsed vulnerable to DDoS amplification attack
From: larry0 () me com
Date: Fri, 04 Oct 2024 15:27:32 +0300
Hello oss-security, Thursday, October 3, 2024 at 2:58 PM -04:00 from peter () 7bits nl <peter () 7bits nl>:
Hello, On Thu, Oct 3, 2024, at 19:54, Larry Cashdollar wrote:I've requested a CVE ID to be able to discern between the RCE and the DoS vulnerability.I reported this as https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq86-c7g6-r2h8 last week, and in the edits at the top (by upstream, above the Summary heading) it looks like they did not want (or did not consider) to request a separate CVE for this. Please do coordinate with them if you decide to go ahead with this request. (I did notice, and can see value in, Will Dormann's suggestion in the other thread that it might make sense to have more fine-grained CVEs for this collection of problems.) -- Peter van Dijk peter () 7bits nl
This vulnerability has been assigned CVE-2024-47850. Thanks, Larry C$
Current thread:
- cups-browsed vulnerable to DDoS amplification attack Larry Cashdollar (Oct 03)
- Re: cups-browsed vulnerable to DDoS amplification attack Peter van Dijk (Oct 03)
- Re: cups-browsed vulnerable to DDoS amplification attack Larry Cashdollar (Oct 03)
- Re[2]: cups-browsed vulnerable to DDoS amplification attack larry0 (Oct 04)
- Re: cups-browsed vulnerable to DDoS amplification attack Peter van Dijk (Oct 03)
