Re: CVE-2019-5599 SACK Slowness (FreeBSD 12 using the RACK TCP Stack)

2019-07-05 Thread Shawn Webb
On Wed, Jul 03, 2019 at 10:18:12AM -0700, Gordon Tetlow wrote: > Sorry for the late response, only so many hours in the day. Completely understood. Thanks for taking the time to respond! > > On Tue, Jun 18, 2019 at 08:06:55PM -0400, Shawn Webb wrote: > > It appears that Netflix's advisory (as of

Re: CVE-2019-5599 SACK Slowness (FreeBSD 12 using the RACK TCP Stack)

2019-07-05 Thread Dan Langille
> On Jul 5, 2019, at 6:40 AM, Shawn Webb wrote: > >> On Wed, Jul 03, 2019 at 10:18:12AM -0700, Gordon Tetlow wrote: >> Sorry for the late response, only so many hours in the day. > > Completely understood. Thanks for taking the time to respond! > >> >>> On Tue, Jun 18, 2019 at 08:06:55PM -0400

Re: CVE-2019-5599 SACK Slowness (FreeBSD 12 using the RACK TCP Stack)

2019-07-05 Thread Shawn Webb
On Fri, Jul 05, 2019 at 07:52:32AM -0700, Dan Langille wrote: > > On Jul 5, 2019, at 6:40 AM, Shawn Webb wrote: > > > >> On Wed, Jul 03, 2019 at 10:18:12AM -0700, Gordon Tetlow wrote: > >> Sorry for the late response, only so many hours in the day. > > > > Completely understood. Thanks for takin

Re: ?Minor Security Issue - DNS, /etc/hosts, freebsd-update, ?pkg

2019-07-05 Thread J. Hellenthal via freebsd-security
And in what revision besides an administrators local modifications suggest that those werre ever a part of the source trree ? For reference ... https://svnweb.freebsd.org/base/stable/11/etc/hosts?view=log Quite frankly the FreeBSD source committers are much more knowledged thann your insight s

Re: Review of FreeBSD Security Advisory Process: Incl Heads Up, Dates, Etc [cont: 5599 SACK}

2019-07-05 Thread grarpamp
On 7/5/19, Peter Jeremy wrote: > On 2019-Jul-04 00:06:10 -0400, grarpamp wrote: >>Continued from beginnings in: >>https://lists.freebsd.org/pipermail/freebsd-security/2019-June/009996.html > What benefits would be gained by Some have been, and more can be by others, outlined in the ongoing thre