HomeFreeBSD

net-p2p/transmission-daemon: Mitigate DNS rebinding attack

Description

net-p2p/transmission-daemon: Mitigate DNS rebinding attack

Incorporate upstream pull request 468, proposed by Tavis Ormandy from
Google Project Zero, which mitigates this attack by requiring a host
whitelist for requests that cannot be proven to be secure, but it can
be disabled if a user does not want security.

PR: 225150
Submitted by: Tavis Ormandy
Approved by: crees (maintainer)
Obtained from: https://github.com/transmission/transmission/pull/468#issuecomment-357098126
MFH: 2018Q1
Security: https://www.vuxml.org/freebsd/3e5b8bd3-0c32-452f-a60e-beab7b762351.html

Details

Provenance
woodsb02Authored on
Parents
rP459010: astro/boinc-setiathome-v7 -> astro/boinc-setiathome-v8
Branches
Unknown
Tags
Unknown