From: Alberto Leiva Popper Date: Mon, 14 Oct 2024 17:32:22 +0000 (-0600) Subject: Name CVE-2024-48943 X-Git-Tag: 1.6.5~4 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=e6856e67ae7ced7e0945f35373a2ccf4e75dfe9b;p=thirdparty%2FFORT-validator.git Name CVE-2024-48943 --- diff --git a/docs/CVE.md b/docs/CVE.md index f6389d8d..9a2a7c1f 100644 --- a/docs/CVE.md +++ b/docs/CVE.md @@ -58,9 +58,7 @@ Certificate containing `signedAttrs` not in canonical form crashes Fort 1.6.2-. | Patch | Commit [521b1a0](https://github.com/NICMx/FORT-validator/commit/521b1a0db5041258096fbabdf8fc1e10ecc793cf), released in Fort 1.6.3. | | Acknowledgments | Thanks to Niklas Vogel and Haya Schulmann for their research and disclosure. | -## CVE-____-_____ - -(Awaiting CVE ID number assignment.) +## CVE-2024-48943 Malicious rsync repositories can block Fort by drip-feeding repository objects.