Hi

Just some good news, my old issue

https://cyrus.topicbox.com/groups/info/T9aaa6a2c6f46f713-M8e510b8b9d2403f299d68854/uid-thread-refs-us-ascii-all-slow-stalls-forever-on-one-folder


I solved with an upgrade from 3.2.5 to 3.4.2

I have not confirmed but I guess the following did it:

Fixed CVE-2021-33582: Certain user inputs are used as hash table keys during processing. A poorly chosen string hashing algorithm meant that the user could control which bucket their data was stored in, allowing a malicious user to direct many inputs to a single bucket. Each subsequent insertion to the same bucket requires a strcmp of every other entry in it. At tens of thousands of entries, each new insertion could keep the CPU busy in a strcmp loop for minutes.

------------------------------------------
Cyrus: Info
Permalink: 
https://cyrus.topicbox.com/groups/info/Tc744853b5c314021-M56b75cda57584b3334768ab8
Delivery options: https://cyrus.topicbox.com/groups/info/subscription

Reply via email to