[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Wed, 11 Nov 2009 20:07:29 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: libjson-ruby: catastrophic backtracking
----- "Michael Gilbert" <michael.s.gilbert@...il.com> wrote:
> hi all,
>
> should a cve id be issued for the following "catastrophic
> backtracking" issue in libjson-ruby?
>
> http://rubyforge.org/frs/shownotes.php?release_id=36363
> http://bugs.debian.org/555516 (note two separate issues fixed there)
>
Can someone elaborate on what "catastrophic backtracking" means? Is this a DoS?
Thanks.
--
JB
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ