Bug#665842: tremulous: traffic amplification via spoofed getstatus requests

2012-03-27 Thread Simon McVittie
Backported patches apply and build, but have not been tested (at all). I'll upload to unstable when I've had a chance to test them. I've asked upstream whether there's anything else non-obvious that will need backporting... S -- To UNSUBSCRIBE, email to

Bug#665842: tremulous: traffic amplification via spoofed getstatus requests

2012-03-26 Thread Simon McVittie
Package: tremulous Version: 1.1.0-5 Severity: serious Tags: security Justification: RC in maintainer's opinion, facilitates DoS against others It has been discovered that spoofed getstatus UDP requests are used by attackers to direct status responses from multiple Quake 3-based servers to a