Re: svnserve DoS attack (1.7.8)

2013-05-22 Thread Daniel Shahaf
On Sun, May 19, 2013 at 11:18:49AM +0200, Stefan Sperling wrote: > On Wed, May 15, 2013 at 02:08:57PM +0400, Boris Lytochkin wrote: > > It is possible to force svnserve daemon to exit using trivial (and valid) > > TCP session: > > Thanks for your bug report and patch, Boris. > We'll release updat

Re: svnserve DoS attack (1.7.8)

2013-05-19 Thread Stefan Sperling
On Wed, May 15, 2013 at 02:08:57PM +0400, Boris Lytochkin wrote: > It is possible to force svnserve daemon to exit using trivial (and valid) TCP > session: Thanks for your bug report and patch, Boris. We'll release updates soon that include a fix for this issue. In the future, please report secu

svnserve DoS attack (1.7.8)

2013-05-15 Thread Boris Lytochkin
Hi. It is possible to force svnserve daemon to exit using trivial (and valid) TCP session: 14:04:18.277961 IP6 fdef::1.34130 > fd87:e01f:53ee:1203:6672:6565:57fa:eb29.3690: Flags [S], seq 3296066821, win 17880, options [mss 1220,nop,nop,sackOK,nop,wscale 7], length 0 14:04:18.278001 IP6 fd87:e