From owner-freebsd-bugs@FreeBSD.ORG Tue Nov 23 23:45:34 2004 Return-Path: Delivered-To: freebsd-bugs@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4829816A50C for ; Tue, 23 Nov 2004 23:45:34 +0000 (GMT) Received: from fledge.watson.org (fledge.watson.org [204.156.12.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id E4F4143D1D for ; Tue, 23 Nov 2004 23:45:33 +0000 (GMT) (envelope-from robert@fledge.watson.org) Received: from fledge.watson.org (localhost [127.0.0.1]) by fledge.watson.org (8.13.1/8.13.1) with ESMTP id iANNhl5b000390; Tue, 23 Nov 2004 18:43:47 -0500 (EST) (envelope-from robert@fledge.watson.org) Received: from localhost (robert@localhost)iANNhlPk000387; Tue, 23 Nov 2004 23:43:47 GMT (envelope-from robert@fledge.watson.org) Date: Tue, 23 Nov 2004 23:43:46 +0000 (GMT) From: Robert Watson X-Sender: robert@fledge.watson.org To: Phil Brennan In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-bugs@freebsd.org Subject: Re: bin/61084: nfsd sometimes exits prematurely during port-scan X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 23 Nov 2004 23:45:34 -0000 On Tue, 23 Nov 2004, Phil Brennan wrote: > The fix for this has not been committed to RELENG_5_2. > src/usr.sbin/nfsd/nfsd.c is still at 1.28, when it should be 1.29. This > is very unfortunate, as it allows a denial of service simply by running > nmap against the box. Could this be committed to this branch also, as > there are quite a lot of people still running 5.2.1. Thanks. ( Just got > bitten by this today ) Regards, I'll put in a request to the re@ team to get this merged ASAP. Thanks for the pointer, and sorry about not having merged it there previously! Robert N M Watson FreeBSD Core Team, TrustedBSD Projects robert@fledge.watson.org Principal Research Scientist, McAfee Research