Re: [Ganglia-developers] CVE

2009-01-26 Thread Stu Teasdale
On Sun, Jan 25, 2009 at 09:49:15PM +, Carlo Marcelo Arenas Belon wrote: On Fri, Jan 23, 2009 at 08:52:45AM -0700, Brad Nicholes wrote: Are we finished hashing this whole patch out yet? haven't seen many comments from other testers of the simplified patch, but considering that it has

Re: [Ganglia-developers] CVE

2009-01-25 Thread Carlo Marcelo Arenas Belon
On Fri, Jan 23, 2009 at 08:52:45AM -0700, Brad Nicholes wrote: Are we finished hashing this whole patch out yet? haven't seen many comments from other testers of the simplified patch, but considering that it has been included already in the 3.1.1 stable package from Gentoo x86, I'd assume it

Re: [Ganglia-developers] CVE

2009-01-23 Thread Spike Spiegel
On Fri, Jan 23, 2009 at 11:52 PM, Brad Nicholes bnicho...@novell.com wrote: * http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0242 Ganglia 3.1.1 allows remote attackers to cause a denial of service via a request to the gmetad service with a path does not exist, which causes Ganglia