Bug#800564: [php-maint] Bug#800564: php5: trivial hash complexity DoS attack

2016-10-02 Thread brian m. carlson
On Mon, Oct 05, 2015 at 12:32:33AM +0200, Ondřej Surý wrote: > On Mon, Oct 5, 2015, at 00:20, brian m. carlson wrote: > > On Sun, Oct 04, 2015 at 09:55:43PM +0200, Ondřej Surý wrote: > > > Hi Brian, > > > > > > did you already reported this to php security or should I do that? > > > > You should

Bug#800564: [php-maint] Bug#800564: php5: trivial hash complexity DoS attack

2015-10-04 Thread Ondřej Surý
On Mon, Oct 5, 2015, at 00:20, brian m. carlson wrote: > On Sun, Oct 04, 2015 at 09:55:43PM +0200, Ondřej Surý wrote: > > Hi Brian, > > > > did you already reported this to php security or should I do that? > > You should probably do that. I already did. > I didn't contact PHP Security or the >

Bug#800564: [php-maint] Bug#800564: php5: trivial hash complexity DoS attack

2015-10-04 Thread brian m. carlson
On Sun, Oct 04, 2015 at 09:55:43PM +0200, Ondřej Surý wrote: > Hi Brian, > > did you already reported this to php security or should I do that? You should probably do that. I didn't contact PHP Security or the Debian Security Team because I expect that due to similar vulnerabilities in other lan

Bug#800564: [php-maint] Bug#800564: php5: trivial hash complexity DoS attack

2015-10-04 Thread Ondřej Surý
Hi Brian, did you already reported this to php security or should I do that? Cheers, Ondrej On Fri, Oct 2, 2015, at 14:37, brian m. carlson wrote: > On Wed, Sep 30, 2015 at 11:27:39PM +, brian m. carlson wrote: > > Package: php5-cli > > Version: 5.6.13+dfsg-2 > > Severity: important > > Tag