From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id A64E71389E2 for ; Sat, 13 Dec 2014 17:08:41 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 4F9E1E0A94; Sat, 13 Dec 2014 17:08:41 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id DDC46E0A94 for ; Sat, 13 Dec 2014 17:08:40 +0000 (UTC) Received: from oystercatcher.gentoo.org (oystercatcher.gentoo.org [148.251.78.52]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 2D55634063A for ; Sat, 13 Dec 2014 17:08:40 +0000 (UTC) Received: by oystercatcher.gentoo.org (Postfix, from userid 2316) id D8370C563; Sat, 13 Dec 2014 17:08:38 +0000 (UTC) From: "Sean Amoss (ackle)" To: gentoo-commits@lists.gentoo.org Reply-To: gentoo-dev@lists.gentoo.org, ackle@gentoo.org Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-201412-16.xml X-VCS-Repository: gentoo X-VCS-Files: glsa-201412-16.xml X-VCS-Directories: xml/htdocs/security/en/glsa X-VCS-Committer: ackle X-VCS-Committer-Name: Sean Amoss Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Message-Id: <20141213170838.D8370C563@oystercatcher.gentoo.org> Date: Sat, 13 Dec 2014 17:08:38 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org X-Archives-Salt: df5280b4-dedd-4f6e-81e4-c049abd3b9ea X-Archives-Hash: e55922ad42c22b8286e90b3ce4d0e62e ackle 14/12/13 17:08:38 Added: glsa-201412-16.xml Log: GLSA 201412-16 Revision Changes Path 1.1 xml/htdocs/security/en/glsa/glsa-201412-16.xml file : http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201412-16.xml?rev=1.1&view=markup plain: http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201412-16.xml?rev=1.1&content-type=text/plain Index: glsa-201412-16.xml =================================================================== CouchDB: Denial of Service A vulnerability in CouchDB could result in Denial of Service. couchdb December 13, 2014 December 13, 2014: 1 506354 remote 1.5.1 1.5.1

Apache CouchDB is a distributed, fault-tolerant and schema-free document-oriented database.

CouchDB does not properly sanitize the count parameter for Universally Unique Identifiers (UUID) requests.

A remote attacker could send a specially crafted request to CouchDB, possibly resulting in a Denial of Service condition.

The /_uuids handler can be disabled in local.ini with the following configuration:

[httpd_global_handlers] _uuids =

All CouchDB users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/couchdb-1.5.1"
CVE-2014-2668 keytoaster ackle