Candidate: CVE-2011-5268 PublicDate: 2013-12-24 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5268 https://projects.duckcorp.org/issues/261 https://projects.duckcorp.org/versions/13 http://www.openwall.com/lists/oss-security/2014/01/02/9 http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122278.html http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122274.html http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121868.html Description: connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_bip: upstream_bip: released (0.8.9-1) lucid_bip: ignored (reached end-of-life) precise_bip: ignored (reached end-of-life) precise/esm_bip: DNE (precise was needs-triage) quantal_bip: ignored (reached end-of-life) raring_bip: ignored (reached end-of-life) saucy_bip: ignored (reached end-of-life) trusty_bip: not-affected (0.8.9-1) trusty/esm_bip: DNE (trusty was not-affected [0.8.9-1]) utopic_bip: not-affected (0.8.9-1) vivid_bip: not-affected (0.8.9-1) vivid/stable-phone-overlay_bip: DNE vivid/ubuntu-core_bip: DNE wily_bip: not-affected (0.8.9-1) xenial_bip: not-affected (0.8.9-1) yakkety_bip: not-affected (0.8.9-1) zesty_bip: not-affected (0.8.9-1) devel_bip: not-affected (0.8.9-1)