Ticket #67 (closed defect: fixed)

Opened 5 years ago

Last modified 5 years ago

PulseAudio has several denial of service issues

Reported by: ossman Owned by: lennart
Milestone: 0.9.6 Component: daemon
Keywords: Cc: cj@…, aluigi@…

Description

Luigi Auriemma has found a number of problems where a client can crash the server. Some of the attacks do not even require the client to be authenticated.

Attachments

pulsex.zip (12.3 kB) - added by ossman 5 years ago.

Change History

Changed 5 years ago by ossman

Changed 5 years ago by cjvdb

  • cc cj@… added

Changed 5 years ago by ossman

  • cc aluigi@… added

Changed 5 years ago by lennart

  • status changed from new to assigned
  • milestone set to 0.9.6

Changed 5 years ago by lennart

(In [1445]) fix a DoS vulnerability (re #67), originally identified by Luigi Auriemma

Changed 5 years ago by lennart

  • status changed from assigned to closed
  • resolution set to fixed

(In [1446]) Fix another DoS vulnerability, also identified Luigi Auriemma (closes #67)

Changed 5 years ago by lennart

  • status changed from closed to reopened
  • resolution fixed deleted

Not closed yet, three more to go...

Changed 5 years ago by lennart

(In [1448]) Fix yet another DoS vulnerability, also identified Luigi Auriemma (re #67)

Changed 5 years ago by lennart

(In [1450]) Fix a DoS with allocating overly large silence buffers. (Identified by Luigi Auriemma (re #67)

Changed 5 years ago by lennart

(In [1451]) add a missing initialization that causes a crash when parsing invalid volume restoration tables (Problem identified by Luigi Auriemma, re #67)

Changed 5 years ago by lennart

  • status changed from reopened to closed
  • resolution set to fixed

(In [1452]) Fix another DoS vulnerability that has been identified by Luigi Auriemma. (Finally closes #67)

Changed 5 years ago by lennart

Lugi, thank you very much for your work. Your work is very much appreciated!

Thanks again,

Lennart

Changed 5 years ago by lennart

Oops, sorry that I misspelled your name, Luigi!

Note: See TracTickets for help on using tickets.