Good day,

In CVE-2002-1265 said :

| The Sun RPC functionality in multiple libc implementations does not
| provide a time-out mechanism when reading data from TCP connections,
| which allows remote attackers to cause a denial of service (hang).

According to http://www.securityfocus.com/bid/6103/info/
Debian glibc has been vulnerable to this.

I have search throw changelogs (both Debian and upstream) but I can't
find any reference to this problem. This seems to be another problem
than CAN-2003-10 "Integer overflow in Sun RPC XDR library routines"
mention in bug #185508

Does anybody know which version fix this?

Regards.
-- 
Djoumé SALVETTI


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to